CVE-2016-3079
Summary
| CVE | CVE-2016-3079 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-04-14 14:59:00 UTC |
| Updated | 2023-02-12 23:18:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1320452 – (CVE-2016-3079) two XSS issues due to element creation in SSM (Perl stack) and displaying outside of it |
CONFIRM |
bugzilla.redhat.com |
|
| 1320444 – (CVE-2016-3079) XSS on pages for entitlements management |
CONFIRM |
bugzilla.redhat.com |
|
| 1320940 – (CVE-2016-3079) CVE-2016-3079 spacewalk-java: Multiple XSS issues in WebUI |
CONFIRM |
bugzilla.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
rhn.redhat.com |
Vendor Advisory |
| 1320444 - typo slipped past. Ugh. · spacewalkproject/spacewalk@982b11c · GitHub |
CONFIRM |
github.com |
|
| 1320452 - Cleaning up some remaining Tag/Group XSS issues · spacewalkproject/spacewalk@b6491eb · GitHub |
CONFIRM |
github.com |
|
| 1320452 - <c:out> is your friend · spacewalkproject/spacewalk@7920542 · GitHub |
CONFIRM |
github.com |
|
| CVE-2016-3079 - Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| 1320444 - Bad bean-message ids and navbar-vars can lead to XSS issues · spacewalkproject/spacewalk@7b9ff9a · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 240415 Red Hat Update for spacewalk-java (RHSA-2016:0590)