CVE-2011-1594
MEDIUMRed Hat Network Satellite - Open Redirect via URL Bounce Parameter
Title source: llmDescription
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
References (4)
Core 4
Core References
Patch, Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2011-1299.html
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=672167
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2011-1594
Scores
CVSS v3
6.5
EPSS
0.0017
EPSS Percentile
38.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Details
CWE
CWE-20
CWE-601
Status
published
Products (4)
Red Hat/Red Hat Enterprise Linux 6
Red Hat/Red Hat Enterprise Linux 7
redhat/network_satellite
redhat/spacewalk
1.6
Published
Feb 05, 2014
Tracked Since
Feb 18, 2026