It was found that application for listing of system groups in Red Hat Network
Satellite Server and Spacewalk services did not properly HTML escape
the content of QueryString. A remote attacker could use this flaw to conduct
XSS attacks, potentially leading into attacker's ability to steal
the users' session cookie.
Acknowledgements:
Red Hat would like to thank Daniel Karanja Muturi for reporting this issue.
Created spacewalk-backend tracking bugs for this issue
Affects: fedora-all [bug 738818]
Comment 13Jan Pazdziora (Red Hat)
2011-09-16 06:41:50 UTC
(In reply to comment #12)
> Created spacewalk-backend tracking bugs for this issue
>
> Affects: fedora-all [bug 738818]
I don't quite understand -- the problem (and the fix) is not in spacewalk-backend package.
Comment 14Jan Pazdziora (Red Hat)
2011-09-16 09:32:20 UTC
Fixed in Spacewalk master, commit 2d9c34e7b682b375ea32595f0dd38b61f424a24f, tagged as spacewalk-java-1.6.46-1.
Sorry, thanks for the Jan. When initially filing this, I suspect some random spacewalk component was selected for the purpose of tracking bugs. Thank you for clearing it up and resolving that invalid tracker.