← Vulnerability feed

Vulnerability record · CVE-2020-1693 · published 17 February 2020

CVE-2020-1693: Redhat spacewalk xml external entity (xxe) vulnerability

Redhat · Spacewalk

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.

9.8 CVSS 3.1 Critical EPSS 4.3% · top 9.3% CWE-611 · XML external entity (XXE)
9.8CVSS 3.1 base score, v2 7.5
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-1693 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-10137Redhat satellite path traversal vulnerabilityA path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthen…EPSS 3.1%9.8CVE-2017-7470Redhat spacewalk incorrect authorization vulnerabilityIt was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorizati…EPSS 2.1%7.5CVE-2018-1077Redhat spacewalk xml external entity (xxe) vulnerabilitySpacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.EPSS 1.0%6.5CVE-2011-1594Redhat network satellite open redirect vulnerabilityA flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…EPSS 1.5%5.5CVE-2011-2920Redhat network satellite cross-site scripting vulnerabilityA flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitra…EPSS 2.0%5.4CVE-2011-3344Redhat network satellite cross-site scripting vulnerabilityA flaw was found in Spacewalk. A remote attacker can exploit a cross-site scripting (XSS) vulnerability in the Lookup Login/Password form by injectin…EPSS 1.5%5.4CVE-2011-2927Redhat network satellite cross-site scripting vulnerabilityA flaw was found in Spacewalk and Red Hat Network Satellite. This vulnerability, known as cross-site scripting (XSS), allows remote attackers to inje…EPSS 1.5%4.3CVE-2019-10136Redhat satellite improper verification of cryptographic signature vulnerabilityIt was found that Spacewalk, all versions through 2.9, did not safely compute client token checksums. An attacker with a valid, but expired, authenti…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2020-1693), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.