VYPR

Spacewalk

by Spacewalk Project

CVEs (1)

  • CVE-2021-40348HigNov 1, 2021
    risk 0.00cvss 8.8epss 0.02

    Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to…