CRITICAL🇵🇱 Wersja polska

CVE-2024-7012

CVSS 9.8v3.1pub. 2024-09-04upd. 2024-11-06

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) and could potentially enable unauthorized users to gain administrative access.

🤖 AI Analysis
How it works

The issue stems from puppet-foreman configuration combined with improper behavior of the Apache mod_proxy module, which does not properly remove HTTP headers containing underscore characters. Due to restrictions on underscores in HTTP headers, mod_proxy does not delete these headers, allowing an attacker to bypass the authentication mechanism by sending a properly crafted (malformed) header. In this way, an attacker can impersonate an authenticated or privileged user without knowledge of their credentials.

Impact

An unauthenticated remote attacker can gain unauthorized administrative access to a Red Hat Satellite deployment, resulting in complete compromise of confidentiality, integrity, and availability of the managed infrastructure.

Mitigation & patch

Apply patches available from the vendor according to the errata: RHSA-2024:6335 (Satellite 6.15), RHSA-2024:6336 (Satellite 6.14), RHSA-2024:6337 (Satellite 6.13), and RHSA-2024:8906. Details available at https://access.redhat.com/security/cve/CVE-2024-7012

Who is affected

Red Hat Satellite versions 6.13, 6.14, and 6.15 deployed with External Authentication and puppet-foreman configuration

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Red Hat Satellite

    APP
    Redhat
    6.136.146.15
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX

CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE — komponent Libraries

CVE-2024-7923CRITICAL9.8PL ✓same product

Authentication bypass w Pulpcore/Red Hat Satellite przez nagłówek HTTP

CVE-2023-0118CRITICAL9.1PL ✓same product

Arbitrary code execution w Foreman — obejście safe mode w szablonach

CVE-2019-17631CRITICAL9.1PL ✓same product

Eclipse OpenJ9: brak kontroli uprawnień do operacji diagnostycznych