A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information.
References
| Link | Resource |
|---|---|
| http://www.redhat.com/support/errata/RHSA-2011-1299.html | Patch Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2011-2920 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=681032 | Vendor Advisory |
| https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html | Vendor Advisory |
| http://www.redhat.com/support/errata/RHSA-2011-1299.html | Patch Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=681032 | Vendor Advisory |
| https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
02 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information. | |
| CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 5.5 |
| References |
|
21 Nov 2024, 01:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.redhat.com/support/errata/RHSA-2011-1299.html - Patch, Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=681032 - Vendor Advisory | |
| References | () https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html - Vendor Advisory |
Information
Published : 2014-02-05 18:55
Updated : 2026-04-02 22:16
NVD link : CVE-2011-2920
Mitre link : CVE-2011-2920
CVE.ORG link : CVE-2011-2920
JSON object : View
Products Affected
redhat
- network_satellite
- spacewalk
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
