Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24634
HistoryApr 10, 2020 - 12:59 a.m.

Privilege Escalation

2020-04-1000:59:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
6

0.002 Low

EPSS

Percentile

52.7%

spacewalk-java is vulnerable to privilege escalation. The vulnerability exists as it was found that RHN Satellite did not protect against Cross-Site Request Forgery (CSRF) attacks. If an authenticated RHN Satellite user visited a specially-crafted web page, it could lead to unauthorized command execution with the privileges of that user, for example, creating a new user account, granting administrator privileges to user accounts, disabling the account of the current user, and so on.

0.002 Low

EPSS

Percentile

52.7%