An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NRed Hat Satellite
APPRedhat6.6Theforeman Foreman Tasks
APPTheforeman< 0.15.7
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Auth Bypass
Powiązane podatności
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
CVE-2024-7923CRITICAL9.8PL ✓ten sam produkt
Authentication bypass w Pulpcore/Red Hat Satellite przez nagłówek HTTP
CVE-2024-7012CRITICAL9.8PL ✓ten sam produkt
Authentication Bypass w Foreman/Red Hat Satellite via zniekształcony nagłówek HTTP
CVE-2023-0118CRITICAL9.1PL ✓ten sam produkt
Arbitrary code execution w Foreman — obejście safe mode w szablonach