vulnerability
Rocky Linux: CVE-2022-4130: Satellite-6.14 (RLSA-2023-6818)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
6 | (AV:N/AC:M/Au:M/C:N/I:C/A:N) | Dec 16, 2022 | Mar 5, 2024 | Jan 30, 2025 |
Severity
6
CVSS
(AV:N/AC:M/Au:M/C:N/I:C/A:N)
Published
Dec 16, 2022
Added
Mar 5, 2024
Modified
Jan 30, 2025
Description
A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.
Solution(s)
rocky-upgrade-libdb-cxxrocky-upgrade-libdb-cxx-debuginforocky-upgrade-libdb-debuginforocky-upgrade-libdb-debugsourcerocky-upgrade-libdb-sql-debuginforocky-upgrade-libdb-sql-devel-debuginforocky-upgrade-libdb-utils-debuginfo

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.