CVE Vulnerabilities

CVE-2022-4130

Published: Dec 16, 2022 | Modified: Feb 06, 2023
CVSS 3.x
4.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Ubuntu

A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attackers server by modifying the Referer header in an HTTP request of specific resources in the server.

Affected Software

Name Vendor Start Version End Version
Satellite Redhat 6.9 (including) 6.9 (including)
Satellite Redhat 6.10 (including) 6.10 (including)
Satellite Redhat 6.11 (including) 6.11 (including)
Red Hat Satellite 6.13 for RHEL 8 RedHat foreman-0:3.5.1.24-1.el8sat *
Red Hat Satellite 6.13 for RHEL 8 RedHat foreman-0:3.5.1.24-1.el8sat *
Red Hat Satellite 6.14 for RHEL 8 RedHat foreman-0:3.7.0.9-1.el8sat *
Red Hat Satellite 6.14 for RHEL 8 RedHat foreman-0:3.7.0.9-1.el8sat *

References