CVE Vulnerabilities

CVE-2022-4130

Published: Dec 16, 2022 | Modified: Apr 14, 2025
CVSS 3.x
4.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attackers server by modifying the Referer header in an HTTP request of specific resources in the server.

Affected Software

NameVendorStart VersionEnd Version
SatelliteRedhat6.9 (including)6.9 (including)
SatelliteRedhat6.10 (including)6.10 (including)
SatelliteRedhat6.11 (including)6.11 (including)
Red Hat Satellite 6.13 for RHEL 8RedHatforeman-0:3.5.1.24-1.el8sat*
Red Hat Satellite 6.13 for RHEL 8RedHatforeman-0:3.5.1.24-1.el8sat*
Red Hat Satellite 6.13 for RHEL 8RedHatforeman-0:3.5.1.24-1.el8sat*
Red Hat Satellite 6.14 for RHEL 8RedHatforeman-0:3.7.0.9-1.el8sat*
Red Hat Satellite 6.14 for RHEL 8RedHatforeman-0:3.7.0.9-1.el8sat*
Red Hat Satellite 6.14 for RHEL 8RedHatforeman-0:3.7.0.9-1.el8sat*

References