An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NRed Hat Satellite
APPRedhat6.6Theforeman Foreman Tasks
APPTheforeman< 0.15.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
Related vulnerabilities
CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓same product
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
CVE-2024-7923CRITICAL9.8PL ✓same product
Authentication bypass w Pulpcore/Red Hat Satellite przez nagłówek HTTP
CVE-2024-7012CRITICAL9.8PL ✓same product
Authentication Bypass w Foreman/Red Hat Satellite via zniekształcony nagłówek HTTP
CVE-2023-0118CRITICAL9.1PL ✓same product
Arbitrary code execution w Foreman — obejście safe mode w szablonach