PT-2014-2509 · Red Hat · Spacewalk-Java+1

Ryan Giobbi

·

Published

2014-04-01

·

Updated

2022-02-03

·

CVE-2013-1869

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions spacewalk-java versions prior to 2.1.148-1 Red Hat Network (RHN) Satellite version 5.6
Description The issue allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and cross-site scripting (XSS) attacks via the return url parameter.
Recommendations For spacewalk-java versions prior to 2.1.148-1, update to version 2.1.148-1 or later. For Red Hat Network (RHN) Satellite version 5.6, consider restricting access to the vulnerable parameter return url until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1869
RHSA-2014:0148

Affected Products

Red Hat Network Satellite
Spacewalk-Java