CVE-2022-4130
Last modified
CVE-2022-4130 is a medium-severity vulnerability rated 4.5/10 on the CVSS scale. A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Satellite | 6.9 |
| Redhat | Satellite | 6.10 |
| Redhat | Satellite | 6.11 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2145254Issue Tracking, Permissions Required, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2145254Issue Tracking, Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-4130?
How severe is CVE-2022-4130?
How do I fix CVE-2022-4130?
Are you affected by CVE-2022-4130?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
