CVE-2024-7923 is a critical authentication bypass vulnerability in Pulpcore, specifically when deployed with Gunicorn versions prior to 22.0 and the puppet-pulpcore configuration. This flaw, stemming from Apache's mod_proxy not properly unsetting headers due to underscore restrictions, allows unauthorized users to gain administrative access to affected Red Hat Satellite deployments (versions 6.13, 6.14, and 6.15) utilizing Pulpcore 3.0+. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.13CPE matchmatch criteria | cpe:2.3:a:redhat:satellite:6.13:*:*:*:*:*:*:* | ||
6.14CPE matchmatch criteria | cpe:2.3:a:redhat:satellite:6.14:*:*:*:*:*:*:* | ||
6.15CPE matchmatch criteria | cpe:2.3:a:redhat:satellite:6.15:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.