A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information.
References
| Link | Resource |
|---|---|
| http://www.redhat.com/support/errata/RHSA-2011-1299.html | Patch Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2011-2920 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=681032 | Vendor Advisory |
| https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html | Vendor Advisory |
| http://www.redhat.com/support/errata/RHSA-2011-1299.html | Patch Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=681032 | Vendor Advisory |
| https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2014-02-05 18:55
Updated : 2026-06-16 23:32
NVD link : CVE-2011-2920
Mitre link : CVE-2011-2920
CVE.ORG link : CVE-2011-2920
JSON object : View
Products Affected
redhat
- spacewalk
- network_satellite
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
