9.8
CVSSv3

CVE-2019-10137

Published: 02/07/2019 Updated: 12/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A path traversal flaw was found in spacewalk-proxy, all versions up to and including 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary files, if they have access to the proxy's filesystem, or can execute arbitrary code in the context of the httpd process.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat satellite 5.0

redhat spacewalk

Vendor Advisories

Synopsis Important: spacewalk-backend and spacewalk-proxy security update Type/Severity Security Advisory: Important Topic An update for spacewalk-backend and spacewalk-proxy is now available for Red Hat Satellite Proxy v 58Red Hat Product Security has rated this update as having a security impact of Impo ...
Impact: Important Public Date: 2019-07-01 CWE: CWE-22 Bugzilla: 1702604: CVE-2019-10137 spacewalk-proxy ...