Lucene search

K

Spacewalk Project Security Vulnerabilities

cve
cve

CVE-2021-40348

Spacewalk 2.10, and derivatives such as Uyuni 2021.08, allows code injection. rhn-config-satellite.pl doesn't sanitize the configuration filename used to append Spacewalk-specific key-value pair. The script is intended to be run by the tomcat user account with Sudo, according to the installation se...

8.8CVSS

8.8AI Score

0.002EPSS

2021-11-01 05:15 AM
36
2