Server-Side Request Forgery Vulnerability in Red Hat Satellite
CVE-2024-12840
5MEDIUM
Summary
CVE-2024-12840 is a server-side request forgery (SSRF) vulnerability identified in Red Hat Satellite. This flaw allows an attacker to exploit a PUT HTTP request made to the /http_proxies/test_connection endpoint. By manipulating the http_proxies variable to resolve to localhost, the attacker can retrieve sensitive information, specifically the localhost banner. This could facilitate further attacks, leading to unauthorized access and data breaches if not promptly addressed. Users of affected versions of Red Hat Satellite are strongly advised to apply the recommended patches to mitigate this security risk.
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Collectors
NVD Database