A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated remote attacker could use this flaw to retrieve the content of certain files and trigger a denial of service, or in certain circumstances, execute arbitrary code on the Spacewalk server.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:redhat:spacewalk:*:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"vendor_product": "redhat:spacewalk",
"extracted_events": [
{
"fixed": "2.9"
}
]
}
]
}