<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2011-2226</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2011-2226</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>15</Number>
        <Date>2025-11-05T05:48:23Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T12:57:51Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-11-05T05:48:23Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2011-2226</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/I57VT5F524VIYHTZ7FTSO52PZYETABZI/#I57VT5F524VIYHTZ7FTSO52PZYETABZI</URL>
      <Description>E-Mail link for SUSE-SU-2011:0917-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AFPYNKHCHHUNVIQ5CZZPJACWKTI4OAO5/#AFPYNKHCHHUNVIQ5CZZPJACWKTI4OAO5</URL>
      <Description>E-Mail link for SUSE-SU-2011:1324-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Studio Onsite 1.3">
      <Branch Type="Product Name" Name="SUSE Studio Onsite 1.3">
        <FullProductName ProductID="SUSE Studio Onsite 1.3" CPE="cpe:/o:suse:sle-studioonsite:1.3">SUSE Studio Onsite 1.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Studio Onsite Runner 1.2">
      <Branch Type="Product Name" Name="SUSE Studio Onsite Runner 1.2">
        <FullProductName ProductID="SUSE Studio Onsite Runner 1.2" CPE="cpe:/o:suse:suse-studio-onsite-runner:1.2">SUSE Studio Onsite Runner 1.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="kiwi4-4.85.1-0.22.9">
      <FullProductName ProductID="kiwi4-4.85.1-0.22.9">kiwi4-4.85.1-0.22.9</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kiwi4-desc-oemboot-4.85.1-0.22.9">
      <FullProductName ProductID="kiwi4-desc-oemboot-4.85.1-0.22.9">kiwi4-desc-oemboot-4.85.1-0.22.9</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kiwi4-desc-vmxboot-4.85.1-0.22.9">
      <FullProductName ProductID="kiwi4-desc-vmxboot-4.85.1-0.22.9">kiwi4-desc-vmxboot-4.85.1-0.22.9</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kiwi4-tools-4.85.1-0.22.9">
      <FullProductName ProductID="kiwi4-tools-4.85.1-0.22.9">kiwi4-tools-4.85.1-0.22.9</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio">
      <FullProductName ProductID="susestudio" CPE="cpe:2.3:a:suse:studio_onsite:*:*:*:*:*:*:*:*">susestudio</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-1.2.1-0.26.1">
      <FullProductName ProductID="susestudio-1.2.1-0.26.1" CPE="cpe:2.3:a:suse:studio_onsite:1.2.1:*:*:*:*:*:*:*">susestudio-1.2.1-0.26.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-bundled-packages">
      <FullProductName ProductID="susestudio-bundled-packages">susestudio-bundled-packages</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-common">
      <FullProductName ProductID="susestudio-common">susestudio-common</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-common-1.2.1-0.26.1">
      <FullProductName ProductID="susestudio-common-1.2.1-0.26.1">susestudio-common-1.2.1-0.26.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-image-helpers-1.2.1-0.3.3">
      <FullProductName ProductID="susestudio-image-helpers-1.2.1-0.3.3">susestudio-image-helpers-1.2.1-0.3.3</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-runner">
      <FullProductName ProductID="susestudio-runner">susestudio-runner</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-runner-1.2.1-0.26.1">
      <FullProductName ProductID="susestudio-runner-1.2.1-0.26.1">susestudio-runner-1.2.1-0.26.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-sid">
      <FullProductName ProductID="susestudio-sid">susestudio-sid</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-ui-server">
      <FullProductName ProductID="susestudio-ui-server">susestudio-ui-server</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="susestudio-ui-server-1.2.1-0.26.1">
      <FullProductName ProductID="susestudio-ui-server-1.2.1-0.26.1">susestudio-ui-server-1.2.1-0.26.1</FullProductName>
    </Branch>
    <Relationship ProductReference="kiwi4-4.85.1-0.22.9" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:kiwi4-4.85.1-0.22.9">kiwi4-4.85.1-0.22.9 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="kiwi4-desc-oemboot-4.85.1-0.22.9" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:kiwi4-desc-oemboot-4.85.1-0.22.9">kiwi4-desc-oemboot-4.85.1-0.22.9 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="kiwi4-desc-vmxboot-4.85.1-0.22.9" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:kiwi4-desc-vmxboot-4.85.1-0.22.9">kiwi4-desc-vmxboot-4.85.1-0.22.9 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="kiwi4-tools-4.85.1-0.22.9" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:kiwi4-tools-4.85.1-0.22.9">kiwi4-tools-4.85.1-0.22.9 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-1.2.1-0.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:susestudio-1.2.1-0.26.1">susestudio-1.2.1-0.26.1 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-common-1.2.1-0.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:susestudio-common-1.2.1-0.26.1">susestudio-common-1.2.1-0.26.1 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-image-helpers-1.2.1-0.3.3" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:susestudio-image-helpers-1.2.1-0.3.3">susestudio-image-helpers-1.2.1-0.3.3 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-runner-1.2.1-0.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:susestudio-runner-1.2.1-0.26.1">susestudio-runner-1.2.1-0.26.1 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-ui-server-1.2.1-0.26.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite Runner 1.2">
      <FullProductName ProductID="SUSE Studio Onsite Runner 1.2:susestudio-ui-server-1.2.1-0.26.1">susestudio-ui-server-1.2.1-0.26.1 as a component of SUSE Studio Onsite Runner 1.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio">susestudio as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-bundled-packages" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-bundled-packages">susestudio-bundled-packages as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-common" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-common">susestudio-common as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-runner" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-runner">susestudio-runner as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-sid" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-sid">susestudio-sid as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="susestudio-ui-server" RelationType="Default Component Of" RelatesToProductReference="SUSE Studio Onsite 1.3">
      <FullProductName ProductID="SUSE Studio Onsite 1.3:susestudio-ui-server">susestudio-ui-server as a component of SUSE Studio Onsite 1.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a pattern listing.</Note>
    </Notes>
    <CVE>CVE-2011-2226</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Studio Onsite Runner 1.2:kiwi4-4.85.1-0.22.9</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:kiwi4-desc-oemboot-4.85.1-0.22.9</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:kiwi4-desc-vmxboot-4.85.1-0.22.9</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:kiwi4-tools-4.85.1-0.22.9</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:susestudio-1.2.1-0.26.1</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:susestudio-common-1.2.1-0.26.1</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:susestudio-image-helpers-1.2.1-0.3.3</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:susestudio-runner-1.2.1-0.26.1</ProductID>
        <ProductID>SUSE Studio Onsite Runner 1.2:susestudio-ui-server-1.2.1-0.26.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:P/A:N</VectorV2>
      </ScoreSetV2>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
