Server-Side Request Forgery Vulnerability in Red Hat Satellite
CVE-2024-12840
5MEDIUM
What is CVE-2024-12840?
CVE-2024-12840 is a server-side request forgery (SSRF) vulnerability identified in Red Hat Satellite. This flaw allows an attacker to exploit a PUT HTTP request made to the /http_proxies/test_connection endpoint. By manipulating the http_proxies variable to resolve to localhost, the attacker can retrieve sensitive information, specifically the localhost banner. This could facilitate further attacks, leading to unauthorized access and data breaches if not promptly addressed. Users of affected versions of Red Hat Satellite are strongly advised to apply the recommended patches to mitigate this security risk.