SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-4139

This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users.

MEDIUM 6.8EPSS 0.82%

Does this matter?

Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying existing user accounts to have administrator access.

CVSS 3.1
6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS
0.82% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-346, CWE-352
Affected
redhat/network satellite server · redhat/spacewalk-java
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.