SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2011-2920

This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field.

MEDIUM 5.5EPSS 2.04%

Does this matter?

Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web pages through various input fields, such as the "Filter by Synopsis" field. This could lead to the execution of malicious code in a user's web browser, potentially compromising user sessions or disclosing sensitive information.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
EPSS
2.04% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
redhat/network satellite · redhat/spacewalk
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.