← Zuruck zu CVEs
CVE-2011-1594
MEDIUM6.5
Beschreibung
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht2/5/2014
Zuletzt geandert4/29/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
redhat:network_satelliteredhat:spacewalk
Schwachen (CWE)
CWE-601CWE-20
Referenzen
http://www.redhat.com/support/errata/RHSA-2011-1299.html(secalert@redhat.com)
https://access.redhat.com/security/cve/CVE-2011-1594(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=672167(secalert@redhat.com)
https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html(secalert@redhat.com)
http://www.redhat.com/support/errata/RHSA-2011-1299.html(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=672167(af854a3a-2127-422b-91ae-364da2661108)
https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.