It was found that application for listing of system groups in Red Hat Network Satellite Server and Spacewalk services did not properly HTML escape the content of QueryString. A remote attacker could use this flaw to conduct XSS attacks, potentially leading into attacker's ability to steal the users' session cookie. Acknowledgements: Red Hat would like to thank Daniel Karanja Muturi for reporting this issue.
This issue has been addressed in following products: Red Hat Network Satellite Server v 5.4 Via RHSA-2011:1299 https://rhn.redhat.com/errata/RHSA-2011-1299.html
Created spacewalk-backend tracking bugs for this issue Affects: fedora-all [bug 738818]
(In reply to comment #12) > Created spacewalk-backend tracking bugs for this issue > > Affects: fedora-all [bug 738818] I don't quite understand -- the problem (and the fix) is not in spacewalk-backend package.
Fixed in Spacewalk master, commit 2d9c34e7b682b375ea32595f0dd38b61f424a24f, tagged as spacewalk-java-1.6.46-1.
Sorry, thanks for the Jan. When initially filing this, I suspect some random spacewalk component was selected for the purpose of tracking bugs. Thank you for clearing it up and resolving that invalid tracker.