CVE-2009-4139
Spacewalk: CSRF in all web portal forms
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cross-site request forgery (CSRF) vulnerability in the Spacewalk Java site packages (aka spacewalk-java) 1.2.39 in Spacewalk, as used in the server in Red Hat Network Satellite 5.3.0 through 5.4.1 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that (1) disable the current user account, (2) add user accounts, or (3) modify user accounts to have administrator privileges.
Vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en los paquetes Spacewalk Java (spacewalk-java) 1.2.39 de Spacewalk, tal como se utiliza en el servidor de Red Hat Network Satellite 5.3.0 hasta la versión 5.4.1 y otros productos, permite a atacantes remotos secuestrar la autenticación de usuarios arbitrarios para peticiones que (1) deshabilitan la cuenta del usuario actual, (2) añaden cuentas de usuarios, o (3) modifican cuentas de usuarios para tener privilegios administrativos.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-12-01 CVE Reserved
- 2011-06-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1025674 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/68074 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.redhat.com/support/errata/RHSA-2011-0879.html | 2017-08-17 |
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=529483 | 2011-06-16 | |
https://access.redhat.com/security/cve/CVE-2009-4139 | 2011-06-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Network Satellite Server Search vendor "Redhat" for product "Network Satellite Server" | 5.3.0 Search vendor "Redhat" for product "Network Satellite Server" and version "5.3.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Network Satellite Server Search vendor "Redhat" for product "Network Satellite Server" | 5.4.0 Search vendor "Redhat" for product "Network Satellite Server" and version "5.4.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Network Satellite Server Search vendor "Redhat" for product "Network Satellite Server" | 5.4.1 Search vendor "Redhat" for product "Network Satellite Server" and version "5.4.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Spacewalk-java Search vendor "Redhat" for product "Spacewalk-java" | 1.2.39 Search vendor "Redhat" for product "Spacewalk-java" and version "1.2.39" | - |
Affected
|