PT-2014-2509 · Red Hat · Spacewalk-Java+1

Ryan Giobbi

·

Publicado

2014-04-01

·

Atualizado

2022-02-03

·

CVE-2013-1869

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions spacewalk-java versions prior to 2.1.148-1 Red Hat Network (RHN) Satellite version 5.6
Description The issue allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks via the return url parameter.
Recommendations For spacewalk-java versions prior to 2.1.148-1, update to version 2.1.148-1 or later. For Red Hat Network (RHN) Satellite version 5.6, consider restricting access to the vulnerable parameter return url until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-1869
RHSA-2014:0148

Produtos afetados

Red Hat Network Satellite
Spacewalk-Java