A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.
History

Mon, 14 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat satellite Utils
CPEs cpe:/a:redhat:satellite_utils:6.13::el8
cpe:/a:redhat:satellite_utils:6.14::el8
Vendors & Products Redhat satellite Utils

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-04-14T18:13:22.554Z

Reserved: 2022-11-23T00:00:00.000Z

Link: CVE-2022-4130

cve-icon Vulnrichment

Updated: 2024-08-03T01:27:54.472Z

cve-icon NVD

Status : Modified

Published: 2022-12-16T16:15:25.173

Modified: 2025-04-14T19:15:34.423

Link: CVE-2022-4130

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-01-16T00:00:00Z

Links: CVE-2022-4130 - Bugzilla