Spacewalk
Vendor:
First CVE: Feb 5, 2014 · Active for 12 years
12
Total CVEs
More Total CVEs than 91% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spacewalk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 5, 2014
12 years ago
Most Recent CVE
Feb 17, 2020
2,353 days ago
CVE Severity & Scoring
Spacewalk12 CVEs
17%
50%
8%
25%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (75.0%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High0 (0.0%)
Unknown3 (25.0%)
User Interaction
None5 (41.7%)
Unknown3 (25.0%)
Required4 (33.3%)
Privileges Required
Low2 (16.7%)
High0 (0.0%)
None7 (58.3%)
Unknown3 (25.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7470CRITICAL It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnC | Jul 27, 2018 | 9.8 | 31 | NO | NO |
CVE-2019-10137CRITICAL A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this | Jul 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-1693CRITICAL A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this | Feb 17, 2020 | 9.8 | 25 | NO | NO |
CVE-2011-1594MEDIUM A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulati | Feb 5, 2014 | 6.5 | 21 | NO | NO |
CVE-2018-1077HIGH Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server. | Mar 14, 2018 | 7.5 | 19 | NO | NO |
CVE-2011-3344MEDIUM A flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injecting arbitrary web script or HTML | Feb 5, 2014 | 5.4 | 19 | NO | NO |
CVE-2011-2927MEDIUM A flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inject malicious web scripts or HTM | Feb 5, 2014 | 5.4 | 19 | NO | NO |
CVE-2011-2920MEDIUM A flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitrary web script or HTML into web | Feb 5, 2014 | 5.5 | 19 | NO | NO |
CVE-2019-10136MEDIUM It was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenticated set of headers could move | Jul 2, 2019 | 4.3 | 17 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite before 5.7.0 allow remote authenticated users to inject arbitrary web script or | Jan 15, 2015 | 3.5 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Spacewalk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.6 | 1 | 7.5 | 1.1% | 0 | 0 |
| 1.6 | 5 | 5.4 | 1.5% | 0 | 0 |