CVE-2011-1594
Severity CVSS v4.0:
Pending analysis
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
05/02/2014
Last modified:
02/04/2026
Description
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:network_satellite:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:spacewalk:1.6:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.redhat.com/support/errata/RHSA-2011-1299.html
- https://access.redhat.com/security/cve/CVE-2011-1594
- https://bugzilla.redhat.com/show_bug.cgi?id=672167
- https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html
- http://www.redhat.com/support/errata/RHSA-2011-1299.html
- https://bugzilla.redhat.com/show_bug.cgi?id=672167
- https://www.redhat.com/archives/spacewalk-announce-list/2011-December/msg00000.html



