5.0 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): HIGH
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): LOW
- Availability impact (A): NONE
Http proxies: satellite: service side request forgery in http proxies
A server-side request forgery exists in Satellite. When a PUT HTTP request is made to /http_proxies/test_connection, when supplied with the http_proxies variable set to localhost, the attacker can fetch the localhost banner.
References
Affected products
Matching in nixpkgs
pkgs.job-security
Job control from anywhere
-
nixos-unstable 0-unstable-2024-04-07
- nixpkgs-unstable 0-unstable-2024-04-07
- nixos-unstable-small 0-unstable-2024-04-07
pkgs.libmodsecurity
ModSecurity v3 library component.
pkgs.xml-security-c
C++ Implementation of W3C security standards for XML
pkgs.modsecurity-crs
The OWASP ModSecurity Core Rule Set is a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls.
pkgs.modsecurity_standalone
Open source, cross-platform web application firewall (WAF)
pkgs.haskellPackages.hackage-security
Hackage security library
pkgs.python311Packages.flask-security
Quickly add security features to your Flask application
pkgs.python312Packages.flask-security
Quickly add security features to your Flask application
pkgs.python311Packages.securityreporter
Python wrapper for the Reporter API
pkgs.python312Packages.securityreporter
Python wrapper for the Reporter API
pkgs.haskellPackages.amazonka-securityhub
Amazon SecurityHub SDK
pkgs.haskellPackages.amazonka-securitylake
Amazon Security Lake SDK
pkgs.haskellPackages.hackage-security-HTTP
Hackage security bindings against the HTTP library
pkgs.python311Packages.azure-mgmt-security
Microsoft Azure Security Center Management Client Library for Python
pkgs.python312Packages.azure-mgmt-security
Microsoft Azure Security Center Management Client Library for Python
pkgs.python311Packages.mypy-boto3-securityhub
Type annotations for boto3 securityhub
-
nixos-unstable boto3-securityhub-1.35.72
- nixpkgs-unstable boto3-securityhub-1.35.72
- nixos-unstable-small boto3-securityhub-1.35.72
pkgs.python312Packages.mypy-boto3-securityhub
Type annotations for boto3 securityhub
-
nixos-unstable boto3-securityhub-1.35.72
- nixpkgs-unstable boto3-securityhub-1.35.72
- nixos-unstable-small boto3-securityhub-1.35.72
pkgs.python311Packages.mypy-boto3-securitylake
Type annotations for boto3 securitylake
-
nixos-unstable boto3-securitylake-1.35.40
- nixpkgs-unstable boto3-securitylake-1.35.40
- nixos-unstable-small boto3-securitylake-1.35.40
pkgs.python312Packages.mypy-boto3-securitylake
Type annotations for boto3 securitylake
-
nixos-unstable boto3-securitylake-1.35.40
- nixpkgs-unstable boto3-securitylake-1.35.40
- nixos-unstable-small boto3-securitylake-1.35.40
pkgs.pantheon.switchboard-plug-security-privacy
Switchboard Security & Privacy Plug
pkgs.python311Packages.google-cloud-securitycenter
Cloud Security Command Center API API client library
pkgs.python312Packages.google-cloud-securitycenter
Cloud Security Command Center API API client library
pkgs.azure-cli-extensions.hardware-security-modules
Microsoft Azure Command-Line Tools AzureDedicatedHSMResourceProvider Extension
pkgs.python311Packages.mypy-boto3-codeguru-security
Type annotations for boto3 codeguru-security
-
nixos-unstable boto3-codeguru-security-1.35.0
- nixpkgs-unstable boto3-codeguru-security-1.35.0
- nixos-unstable-small boto3-codeguru-security-1.35.0
pkgs.python312Packages.mypy-boto3-codeguru-security
Type annotations for boto3 codeguru-security
-
nixos-unstable boto3-codeguru-security-1.35.0
- nixpkgs-unstable boto3-codeguru-security-1.35.0
- nixos-unstable-small boto3-codeguru-security-1.35.0
pkgs.python311Packages.types-aiobotocore-securityhub
Type annotations for aiobotocore securityhub
pkgs.python312Packages.types-aiobotocore-securityhub
Type annotations for aiobotocore securityhub
pkgs.python311Packages.types-aiobotocore-securitylake
Type annotations for aiobotocore securitylake
pkgs.python312Packages.types-aiobotocore-securitylake
Type annotations for aiobotocore securitylake
pkgs.python311Packages.google-cloud-websecurityscanner
Google Cloud Web Security Scanner API client library
pkgs.python312Packages.google-cloud-websecurityscanner
Google Cloud Web Security Scanner API client library
pkgs.python311Packages.types-aiobotocore-codeguru-security
Type annotations for aiobotocore codeguru-security
pkgs.python312Packages.types-aiobotocore-codeguru-security
Type annotations for aiobotocore codeguru-security
pkgs.gnomeExtensions.arch-linux-updates-and-security-indicator
Update indicator for Arch Linux and GNOME Shell.
pkgs.python311Packages.microsoft-security-utilities-secret-masker
A tool for detecting and masking secrets
pkgs.python312Packages.microsoft-security-utilities-secret-masker
A tool for detecting and masking secrets
Package maintainers
-
@katexochen Paul Meyer <katexochen0@gmail.com>
-
@ulrikstrid Ulrik Strid <ulrik.strid@outlook.com>
-
@honnip Jung seungwoo <me@honnip.page>
-
@fgaz Francesco Gazzetta <fgaz@fgaz.me>
-
@Izorkin Yurii Izorkin <Izorkin@gmail.com>
-
@offlinehacker Jaka Hudoklin <jaka@x-truder.net>
-
@bobby285271 Bobby Rong <rjl931189261@126.com>
-
@davidak David Kleuker <post@davidak.de>
-
@gador Florian Brandes <florian.brandes@posteo.de>
-
@mbalatsko Maksym Balatsko <mbalatsko@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@jagajaga Arseniy Seroka <ars.seroka@gmail.com>