Skip to main content

Vendor/product archive

redhat / spacewalk CVEs

Beta · best-effort

12 CVEs tagged to redhat / spacewalk0 Critical, 3 High, 7 Medium, 2 Low, 0 Unrated.

CVE-2020-1693

Published Feb 17, 2020

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10137

Published Jul 2, 2019

A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use thi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10136

Published Jul 2, 2019

It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could mov…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7470

Published Jul 27, 2018

It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhn…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3344

Published Feb 5, 2014

A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2927

Published Feb 5, 2014

A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HT…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2920

Published Feb 5, 2014

A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2919

Published Feb 5, 2014

Cross-site scripting (XSS) vulnerability in Spacewalk 1.6, as used in Red Hat Network (RHN) Satellite, allows remote attackers to inject arbitrary web script or HTML via the Query…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1