Bug 731647 (CVE-2011-3344)

Summary: CVE-2011-3344 Satellite/Spacewalk: XSS on the Lost Password page
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: cperry, jlieskov, jpazdziora, nag-redhat, security-response-team, vdanen
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-15 21:19:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On: 736185    
Bug Blocks: 713496    

Description Tomas Hoger 2011-08-18 08:26:00 UTC
A cross-site scripting flaw was discovered in the Lookup Login/Password form of the RHN Satellite and Spacewalk.

https://rhnhost/help/forgot_password.pxt/%22onmouseover=alert%281%29%3E

Acknowledgements:

Red Hat would like to thank Sylvain Maes for reporting this issue.

Comment 3 Vincent Danen 2011-09-06 23:01:39 UTC
This issue has been given the name CVE-2011-3344.

Comment 5 errata-xmlrpc 2011-09-15 17:55:41 UTC
This issue has been addressed in following products:

  Red Hat Network Satellite Server v 5.4

Via RHSA-2011:1299 https://rhn.redhat.com/errata/RHSA-2011-1299.html

Comment 6 Jan Pazdziora 2011-09-16 09:34:53 UTC
Fixed in Spacewalk master, commit 890781d7ec983e32fe83af2f7c033d087292851f,
tagged as spacewalk-web-1.6.21-1.