Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1156299 - (CVE-2014-7811) CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
CVE-2014-7811 Red Hat Satellite, Spacewalk: multiple XSS
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
Jan Hutař
impact=moderate,public=20150112,repor...
: Security
Depends On: 1156304 1156307
Blocks: 1144629
  Show dependency treegraph
 
Reported: 2014-10-24 02:43 EDT by Kurt Seifried
Modified: 2016-02-15 07:04 EST (History)
12 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-01-12 13:08:50 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
SW-master/Sat5-latest patch (10.11 KB, patch)
2014-10-27 14:30 EDT, Grant Gainey
no flags Details | Diff
Sat5.6 patch (9.89 KB, patch)
2014-10-29 13:20 EDT, Grant Gainey
no flags Details | Diff


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0033 normal SHIPPED_LIVE Moderate: Red Hat Satellite 5.7.0 General Availability 2015-01-13 17:23:58 EST

  None (edit)
Description Kurt Seifried 2014-10-24 02:43:18 EDT
Mickaël Gallier reports:

There are several stored XSS vulnerabilities in various fields in Satellite 
server, they can be exploited by using the REST API to send XML data 
containing malformed data.
Comment 3 Grant Gainey 2014-10-27 14:30:09 EDT
Created attachment 951111 [details]
SW-master/Sat5-latest patch

This patch applies to the latest Spacewalk and Satellite5 codebase.  Sat5.6 patch is still in progress.
Comment 4 Grant Gainey 2014-10-29 13:20:24 EDT
Created attachment 951859 [details]
Sat5.6 patch

This patch applies to the 5.6 branch of the Satellite codebase
Comment 6 Kurt Seifried 2015-01-09 12:26:12 EST
Acknowledgement:

Red Hat would like to thank Mickaël Gallier for reporting this issue.
Comment 15 errata-xmlrpc 2015-01-12 12:12:44 EST
This issue has been addressed in the following products:

  Red Hat Satellite Server v 5.7

Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
Comment 16 errata-xmlrpc 2015-01-13 12:27:10 EST
This issue has been addressed in the following products:

  Red Hat Satellite Server v 5.7

Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html

Note You need to log in before you can comment on or make changes to this bug.