CVE-2018-1077: Red Hat Satellite

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

Affected products

  • Red Hat Satellite: version 5.0 only
  • Red Hat Spacewalk: version 2.6 only

Published 2018-03-14. Last modified 2026-06-17.