Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2011-04-18 17:55
Updated : 2025-04-11 00:51
NVD link : CVE-2010-1171
Mitre link : CVE-2010-1171
CVE.ORG link : CVE-2010-1171
JSON object : View
Products Affected
redhat
- satellite
CWE
CWE-264
Permissions, Privileges, and Access Controls