ZeroHour

CVE-2022-4130

CVSS 3.1
4.5 medium
EPSS
<1%p50
Published
()
Modified
Description

A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.

Vendors
redhat
Products
satellite
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.