VulnerabilityModified
CVE-2009-4139
This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users.
MEDIUM 6.8EPSS 0.82%
Does this matter?
Lower severity and a low EPSS score (0.82%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or escalating privileges by modifying existing user accounts to have administrator access.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-346, CWE-352
- Affected
- redhat/network satellite server · redhat/spacewalk-java
- Source
- secalert@redhat.com
References
- http://securitytracker.com/id?1025674
- http://www.redhat.com/support/errata/RHSA-2011-0879.htmlPatch, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-4139
- https://bugzilla.redhat.com/show_bug.cgi?id=529483
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68074
- http://securitytracker.com/id?1025674
- http://www.redhat.com/support/errata/RHSA-2011-0879.htmlPatch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=529483
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68074
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.