Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24509
HistoryApr 10, 2020 - 12:56 a.m.

Authentication Bypass

2020-04-1000:56:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.006

Percentile

79.0%

spacewalk-config is vulnerable to authentication bypass. The vulnerability exists as a flaw was found in the way RHN Satellite rewrote certain URLs. An unauthenticated user could use a specially-crafted HTTP request to obtain sensitive information about the host system RHN Satellite was running on. They could also use RHN Satellite as a distributed denial of service tool, forcing it to connect to an arbitrary service at an arbitrary IP address via a specially-crafted HTTP request.

EPSS

0.006

Percentile

79.0%

Related for VERACODE:24509