PT-2022-25801 · Unknown+2 · Satellite Server+2

Ybuenos

·

Published

2022-12-16

·

Updated

2025-03-26

·

CVE-2022-4130

CVSS v3.1

4.5

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Satellite server (affected versions not specified)
Description A blind site-to-site request forgery issue was discovered. It allows triggering an external interaction to an attacker's server by modifying the Referer header in an HTTP request for specific server resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2025-4484
CVE-2022-4130
RHSA-2023:6818
RHSA-2024:1061

Affected Products

Alt Linux
Rocky Linux
Satellite Server