Red Hat Satellite and Spacewalk CVE-2019-10137 Directory Traversal Vulnerability
BID:108962
Info
Red Hat Satellite and Spacewalk CVE-2019-10137 Directory Traversal Vulnerability
| Bugtraq ID: | 108962 |
| Class: | Design Error |
| CVE: |
CVE-2019-10137 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2019 12:00AM |
| Updated: | Apr 24 2019 12:00AM |
| Credit: | Malte Kraus (SUSE) |
| Vulnerable: |
Redhat Spacewalk 2.8 Redhat Satellite 5 |
| Not Vulnerable: | |
Discussion
Red Hat Satellite and Spacewalk CVE-2019-10137 Directory Traversal Vulnerability
Red Hat Satellite and Spacewalk are prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to write or retrieve arbitrary files from the affected system in the context of the application. Information obtained could aid in further attacks.
spacewalk version 2.8 is vulnerable; other versions may also be affected.
Red Hat Satellite and Spacewalk are prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
Remote attackers may use a specially crafted request with directory-traversal sequences ('../') to write or retrieve arbitrary files from the affected system in the context of the application. Information obtained could aid in further attacks.
spacewalk version 2.8 is vulnerable; other versions may also be affected.
Exploit / POC
Red Hat Satellite and Spacewalk CVE-2019-10137 Directory Traversal Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Red Hat Satellite and Spacewalk CVE-2019-10137 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Red Hat Satellite and Spacewalk CVE-2019-10137 Directory Traversal Vulnerability
References:
References:
- Spacewalk Homepage (Red Hat)
- CVE-2019-10137 (Red Hat)
- CVE-2019-10137 spacewalk-proxy: Path traversal in proxy authentication cache (Red Hat Bugzilla)