← Back

CVE-2022-4130

nvd nist
Published: Dec 16, 2022Modified: Jun 17, 2026

JSON object

Loading...
4.5
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD

Description

A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.

Affected (3)

Products: Redhat: Satellite
1 product
Satellite
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.10
Version 6.11
Version 6.9

References (2)

Source: secalert@redhat.com
Issue TrackingPermissions RequiredVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPermissions RequiredVendor Advisory

Timeline

No history available yet.