Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: paretosecurity

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2024-12840
5.0 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): NETWORK
  • Attack complexity (AC): HIGH
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): LOW
  • Availability impact (A): NONE
created 6 months ago
Http proxies: satellite: service side request forgery in http proxies

A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner.

References

Affected products

security

Matching in nixpkgs

pkgs.paretosecurity

Agent that makes sure your laptop is correctly configured for security

  • nixos-unstable -

pkgs.xml-security-c

C++ Implementation of W3C security standards for XML

  • nixos-unstable -

pkgs.modsecurity-crs

The OWASP ModSecurity Core Rule Set is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls.

  • nixos-unstable -

Package maintainers