<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Red Hat Satellite</title>
  <link>https://cvedaily.com/pages/tags/redhat-satellite.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/redhat-satellite.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Red Hat Satellite</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-4324 – A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4324</guid>
    <pubDate>Tue, 17 Mar 2026 14:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4324</strong></p>
  <p>A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_images API endpoint. This can lead to a Denial of Service (DoS) by triggering database errors, and potentially enable Boolean-based Blind SQL injection,…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-0980 – A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0980</guid>
    <pubDate>Fri, 27 Feb 2026 08:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0980</strong></p>
  <p>A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10622 – A flaw was found in Red Hat Satellite (Foreman component). This vulnerability al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10622</guid>
    <pubDate>Wed, 05 Nov 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10622</strong></p>
  <p>A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-2157 – A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2157</guid>
    <pubDate>Sat, 15 Mar 2025 07:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-2157</strong></p>
  <p>A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-922</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-4142 – The Candlepin component of Red Hat Satellite was affected by an improper authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-4142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-4142</guid>
    <pubDate>Wed, 24 Aug 2022 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-4142</strong></p>
  <p>The Candlepin component of Red Hat Satellite was affected by an improper authentication flaw. Few factors could allow an attacker to use the SCA (simple content access) certificate for authentication with Candlepin.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-4142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10710 – A flaw was found where the Plaintext Candlepin password is disclosed while updat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10710</guid>
    <pubDate>Tue, 16 Aug 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10710</strong></p>
  <p>A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14380 – An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14380</guid>
    <pubDate>Wed, 02 Jun 2021 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14380</strong></p>
  <p>An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14371 – A credential leak vulnerability was found in Red Hat Satellite. This flaw expose...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14371</guid>
    <pubDate>Wed, 02 Jun 2021 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14371</strong></p>
  <p>A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-14335 – A flaw was found in Red Hat Satellite, which allows a privileged attacker to rea...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14335</guid>
    <pubDate>Wed, 02 Jun 2021 12:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-14335</strong></p>
  <p>A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The highest threat from this vulnerability is to system availability.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10716 – A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10716</guid>
    <pubDate>Thu, 27 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10716</strong></p>
  <p>A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible versions before 4.0.3.4.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-3413 – A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3413</guid>
    <pubDate>Thu, 08 Apr 2021 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-3413</strong></p>
  <p>A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-20256 – A flaw was found in Red Hat Satellite. The BMC interface exposes the password th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-20256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-20256</guid>
    <pubDate>Tue, 23 Feb 2021 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-20256</strong></p>
  <p>A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-20256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14334 – A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14334</guid>
    <pubDate>Fri, 31 Jul 2020 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14334</strong></p>
  <p>A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-3590 – Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a cor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3590</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3590</guid>
    <pubDate>Thu, 02 Jan 2020 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-3590</strong></p>
  <p>Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3590">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3891 – It was discovered that a world-readable log file belonging to Candlepin componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3891</guid>
    <pubDate>Mon, 15 Apr 2019 12:31:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3891</strong></p>
  <p>It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-14666 – An improper authorization flaw was found in the Smart Class feature of Foreman. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14666</guid>
    <pubDate>Tue, 22 Jan 2019 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-14666</strong></p>
  <p>An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2017-7514 – A cross-site scripting (XSS) flaw was found in how the failed action entry is pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7514</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7514</guid>
    <pubDate>Mon, 30 Jul 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2017-7514</strong></p>
  <p>A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7514">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2017-12175 – Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-12175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-12175</guid>
    <pubDate>Thu, 26 Jul 2018 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2017-12175</strong></p>
  <p>Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-12175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2017-15136 – When registering and activating a new system with Red Hat Satellite 6 if the new...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15136</guid>
    <pubDate>Tue, 27 Feb 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2017-15136</strong></p>
  <p>When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.</p>
  <p><strong>CVSS:</strong> 2.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5164 – The Qpid server on Red Hat Satellite 6 does not properly restrict message types,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5164</guid>
    <pubDate>Wed, 18 Oct 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5164</strong></p>
  <p>The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8163 – Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8163</guid>
    <pubDate>Mon, 28 Aug 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8163</strong></p>
  <p>Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8168 – Red Hat Satellite 6 allows local users to access mongod and delete pulp_database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8168</guid>
    <pubDate>Mon, 28 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8168</strong></p>
  <p>Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0141 – Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0141</guid>
    <pubDate>Mon, 28 Aug 2017 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0141</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in Red Hat Satellite 6.0.3.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8180 – MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by lo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8180</guid>
    <pubDate>Tue, 06 Jun 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8180</strong></p>
  <p>MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-2104 – Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2104</guid>
    <pubDate>Thu, 13 Apr 2017 14:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-2104</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) <input:hidden> or (6) <bean:message> tags.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-3097 – Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3097</guid>
    <pubDate>Fri, 05 Aug 2016 14:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-3097</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-3080 – Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3080</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3080</guid>
    <pubDate>Fri, 05 Aug 2016 14:59:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-3080</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters, related to display of monitoring probes.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3080">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-3079 – Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3079</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3079</guid>
    <pubDate>Thu, 14 Apr 2016 14:59:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-3079</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3079">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2016-2103 – Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2103</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2103</guid>
    <pubDate>Thu, 14 Apr 2016 14:59:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2016-2103</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2103">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-0284 – Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0284</guid>
    <pubDate>Thu, 14 Apr 2016 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-0284</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in spacewalk-java in Spacewalk and Red Hat Satellite 5.7 allows remote authenticated users to inject arbitrary web script or HTML via crafted XML data to the XMLRPC API, involving user details.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-7811.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2143 – The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2143</guid>
    <pubDate>Thu, 17 Apr 2014 14:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2143</strong></p>
  <p>The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4480 – Red Hat Satellite 5.6 and earlier does not disable the web interface that is use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4480</guid>
    <pubDate>Mon, 18 Nov 2013 02:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4480</strong></p>
  <p>Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4480">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
