CVE-2011-2927
Last modified
CVE-2011-2927 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. EPSS estimates a 1.47% chance of exploitation in the next 30 days.
Description
A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTML into web pages viewed by other users. The flaw is triggered through vectors related to Search forms, enabling attackers to potentially steal sensitive information or perform actions on behalf of the victim.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Network Satellite | All versions |
| Redhat | Spacewalk | 1.6 |
References
- http://www.redhat.com/support/errata/RHSA-2011-1299.htmlPatch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=730955Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2011-1299.htmlPatch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=730955Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2927?
How severe is CVE-2011-2927?
How do I fix CVE-2011-2927?
Are you affected by CVE-2011-2927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
