Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2010-1171

Опубликовано: 11 апр. 2011
Источник: redhat
CVSS2: 5.5
EPSS Низкий

Описание

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 5.0ServerWill not fix
Red Hat Satellite 5.1ServerWill not fix
Red Hat Satellite 5.2ServerAffected
Red Hat Network Satellite Server v 5.3spacewalk-backendFixedRHSA-2011:043411.04.2011
Red Hat Network Satellite Server v 5.3spacewalk-configFixedRHSA-2011:043411.04.2011
Red Hat Network Satellite Server v 5.4spacewalk-backendFixedRHSA-2011:043411.04.2011
Red Hat Network Satellite Server v 5.4spacewalk-configFixedRHSA-2011:043411.04.2011

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=584118rhn_satellite: Improper channel comps information management

EPSS

Процентиль: 76%
0.00958
Низкий

5.5 Medium

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.

github
почти 4 года назад

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.

EPSS

Процентиль: 76%
0.00958
Низкий

5.5 Medium

CVSS2