Bug 882000 (CVE-2012-6149) - CVE-2012-6149 Satellite, Spacewalk (spacewalk-java): XSS in system.addNote XML-RPC call due improper sanitization of note's subject and content
Summary: CVE-2012-6149 Satellite, Spacewalk (spacewalk-java): XSS in system.addNote XM...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-6149
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact: Lukas Pramuk
URL:
Whiteboard:
Depends On: 1022687
Blocks: 883016 915998 1011743
TreeView+ depends on / blocked
 
Reported: 2012-11-29 23:00 UTC by Ben Ford
Modified: 2023-05-12 20:26 UTC (History)
13 users (show)

Fixed In Version: spacewalk-java-2.0.2-57-sat
Clone Of:
Environment:
Last Closed: 2014-02-11 13:09:02 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:0148 0 normal SHIPPED_LIVE Moderate: spacewalk-java, spacewalk-web and satellite-branding security update 2014-02-10 22:29:32 UTC

Comment 4 Jan Lieskovsky 2012-12-03 15:21:37 UTC
A cross-site scripting (XSS) flaw was found in the way the web interface of Red Hat Network Satellite / Spacewalk performed sanitization of note's subject and note's content values, for a note being added after system.addNote() XML-RPC request. A remote authenticated Red Hat Network Satellite / Spacewalk user (having systems registered to particular Red Hat Network Satellite / Spacewalk instance) could use this flaw to execute arbitrary HTML or web script, via specially-crafted XML-RPC request, in the context of the session of Red Hat Network Satellite / Spacewalk administrator, if they visited the page, created as a result of that XML-RPC call.

Comment 5 Jan Lieskovsky 2012-12-10 17:53:18 UTC
Acknowledgements:

Red Hat would like to thank Ben Ford of Puppet Labs for reporting this issue.

Comment 11 errata-xmlrpc 2014-02-10 17:32:57 UTC
This issue has been addressed in following products:

  Red Hat Satellite Server v 5.6

Via RHSA-2014:0148 https://rhn.redhat.com/errata/RHSA-2014-0148.html


Note You need to log in before you can comment on or make changes to this bug.