Unrated severityNVD Advisory· Published Jul 30, 2018· Updated Aug 5, 2024
CVE-2017-7514
CVE-2017-7514
Description
A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.
Affected products
17- osv-coords16 versionspkg:rpm/suse/nutch&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/release-notes-susemanager&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/salt-netapi-client&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacecmd&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk-backend&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk-branding&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk-certs-tools&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk-java&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk-reports&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/spacewalk-web&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/supportutils-plugin-susemanager&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/susemanager&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/susemanager-docs_en&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/susemanager-schema&distro=SUSE%20Manager%20Server%203.0pkg:rpm/suse/susemanager-sls&distro=SUSE%20Manager%20Server%203.0
< 1.0-0.9.5.4+ 15 more
- (no CPE)range: < 1.0-0.9.5.4
- (no CPE)range: < 3.0.9-0.53.9.2
- (no CPE)range: < 0.13.0-16.6.4
- (no CPE)range: < 2.5.5.9-16.9.4
- (no CPE)range: < 2.5.24.14-26.11.4
- (no CPE)range: < 2.5.2.15-16.6.4
- (no CPE)range: < 2.5.1.11-21.6.4
- (no CPE)range: < 2.5.0.7-4.6.4
- (no CPE)range: < 2.5.59.18-27.9.4
- (no CPE)range: < 2.5.1.3-4.3.4
- (no CPE)range: < 2.5.7.19-25.9.4
- (no CPE)range: < 3.0.5-2.3.4
- (no CPE)range: < 3.0.24-25.6.4
- (no CPE)range: < 3-25.8.2
- (no CPE)range: < 3.0.22-25.6.4
- (no CPE)range: < 0.1.24-27.9.4
- Red Hat/Red Hat Satellitev5Range: 5.8.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- access.redhat.com/errata/RHSA-2017:1558mitrevendor-advisoryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.