Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described was inteded behavior and therefore not a bug.
History

Mon, 12 May 2025 21:45:00 +0000


Mon, 12 May 2025 21:15:00 +0000

Type Values Removed Values Added
Title Http proxies: satellite: service side request forgery in http proxies http proxies: Satellite: Service side request forgery in http proxies
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 May 2025 20:30:00 +0000

Type Values Removed Values Added
Description A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner. Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described was inteded behavior and therefore not a bug.
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite

Tue, 24 Dec 2024 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 21 Dec 2024 02:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 20 Dec 2024 16:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner.
Title Http proxies: satellite: service side request forgery in http proxies
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-918
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: REJECTED

Assigner: redhat

Published: 2024-12-20T15:47:17.402Z

Updated: 2025-05-12T20:16:41.146Z

Reserved: 2024-12-20T12:10:24.705Z

Link: CVE-2024-12840

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2024-12-20T16:15:23.417

Modified: 2025-05-12T21:15:46.300

Link: CVE-2024-12840

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-12-20T12:20:00Z

Links: CVE-2024-12840 - Bugzilla