CVE-2016-3079
MEDIUMRed Hat Satellite 5.7 - Stored Cross-Site Scripting via PATH_INFO or Label Parameter
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).
References (8)
Core 8
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1320444
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-0590.html
Patch x_refsource_confirm
https://github.com/spacewalkproject/spacewalk/commit/7b9ff9ad
Patch x_refsource_confirm
https://github.com/spacewalkproject/spacewalk/commit/b6491eba
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1320452
Patch x_refsource_confirm
https://github.com/spacewalkproject/spacewalk/commit/982b11c9
Patch x_refsource_confirm
https://github.com/spacewalkproject/spacewalk/commit/7920542f
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1320940
Scores
CVSS v3
6.1
EPSS
0.0158
EPSS Percentile
72.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
redhat/satellite
5.7
redhat/spacewalk-java
Published
Apr 14, 2016
Tracked Since
Feb 18, 2026