← Vulnerability feed

Vulnerability record · CVE-2011-1594 · published 5 February 2014

CVE-2011-1594: Redhat network satellite open redirect vulnerability

Redhat · Network Satellite

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.

6.5 CVSS 3.1 Medium EPSS 1.5% · top 27.3% CWE-601 · Open redirectCWE-20 · Improper input validation
6.5CVSS 3.1 base score, v2 5.8
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
7References
16 Jun 2026Last modified by NVD

Description

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to arbitrary web sites by manipulating a URL in the url_bounce parameter. This can enable attackers to conduct phishing attacks, potentially leading to unauthorized information disclosure or credential theft.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-1594 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1693Redhat spacewalk xml external entity (xxe) vulnerabilityA flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …EPSS 4.3%9.8CVE-2019-10137Redhat satellite path traversal vulnerabilityA path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…EPSS 3.1%9.8CVE-2017-7470Redhat spacewalk incorrect authorization vulnerabilityIt was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…EPSS 2.1%7.5CVE-2018-1077Redhat spacewalk xml external entity (xxe) vulnerabilitySpacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.EPSS 1.0%7.5CVE-2014-8162Redhat network satellite vulnerabilityXML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbit…EPSS 2.7%7.5CVE-2013-4480Redhat network satellite exposure of resource to wrong sphere vulnerabilityRed Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attac…EPSS 2.1%6.5CVE-2013-2143Katello and Red Hat Satellite missing authorization in update_rolesThe users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action. A remote authe…EPSS 48%analysed5.5CVE-2011-2920Redhat network satellite cross-site scripting vulnerabilityA flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitra…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2011-1594), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.