CVE-2009-4139
Cross-site request forgery (CSRF) vulnerability in the Spacewalk Java site packages (aka spacewalk-java) 1.2.39 in Spacewalk, as used in the server in Red Hat Network Satellite 5.3.0 through 5.4.1 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that (1) disable the current user account, (2) add user accounts, or (3) modify user accounts to have administrator privileges.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.17%
- CWE
- CWE-346
- Published
- 2011-07-27
- Last modified
- 2026-04-28
Affected products
- n/a n/a
Weakness type
Related vulnerabilities
- CVE-2025-34291 — Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
- CVE-2026-54069 — SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
- CVE-2025-9265 — API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
- CVE-2025-69258 — A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta
- CVE-2026-22794 — Account Takeover Vulnerability in Appsmith
- CVE-2025-59159 — SillyTavern Web Interface Vulnerable to DNS Rebinding
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2024-14006 — Nagios XI < 2024R1.2.2 Host Header Injection