Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1172934 - (CVE-2014-7812) CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
CVE-2014-7812 Red Hat Satellite, Spacewalk: XSS in system-group
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
Jan Hutař
impact=moderate,public=20150112,repor...
: Security
Depends On: 1156307
Blocks: 1144629
  Show dependency treegraph
 
Reported: 2014-12-11 01:27 EST by Kurt Seifried
Modified: 2016-02-15 05:25 EST (History)
8 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-01-12 13:08:59 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0033 normal SHIPPED_LIVE Moderate: Red Hat Satellite 5.7.0 General Availability 2015-01-13 17:23:58 EST

  None (edit)
Description Kurt Seifried 2014-12-11 01:27:10 EST
Mickaël Gallier reports:

There are several stored XSS vulnerabilities in various fields in Satellite 
server, they can be exploited by using the REST API to send XML data 
containing malformed data. 

One of these is in the system-group handling. Please see CVE-014-7811 for 
the other vulnerabilities.
Comment 2 Kurt Seifried 2015-01-09 12:25:58 EST
Acknowledgement:

Red Hat would like to thank Mickaël Gallier for reporting this issue.
Comment 6 errata-xmlrpc 2015-01-12 12:12:51 EST
This issue has been addressed in the following products:

  Red Hat Satellite Server v 5.7

Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html
Comment 7 errata-xmlrpc 2015-01-13 12:27:14 EST
This issue has been addressed in the following products:

  Red Hat Satellite Server v 5.7

Via RHSA-2015:0033 https://rhn.redhat.com/errata/RHSA-2015-0033.html

Note You need to log in before you can comment on or make changes to this bug.