Server-Side Request Forgery Vulnerability in Red Hat Satellite

CVE-2024-12840

5MEDIUM

Key Information

Vendor
Red Hat
Vendor
CVE Published:
20 December 2024

Summary

CVE-2024-12840 is a server-side request forgery (SSRF) vulnerability identified in Red Hat Satellite. This flaw allows an attacker to exploit a PUT HTTP request made to the /http_proxies/test_connection endpoint. By manipulating the http_proxies variable to resolve to localhost, the attacker can retrieve sensitive information, specifically the localhost banner. This could facilitate further attacks, leading to unauthorized access and data breaches if not promptly addressed. Users of affected versions of Red Hat Satellite are strongly advised to apply the recommended patches to mitigate this security risk.

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Collectors

NVD Database
.