An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) and could potentially enable unauthorized users to gain administrative access.
The issue stems from puppet-foreman configuration combined with improper behavior of the Apache mod_proxy module, which does not properly remove HTTP headers containing underscore characters. Due to restrictions on underscores in HTTP headers, mod_proxy does not delete these headers, allowing an attacker to bypass the authentication mechanism by sending a properly crafted (malformed) header. In this way, an attacker can impersonate an authenticated or privileged user without knowledge of their credentials.
An unauthenticated remote attacker can gain unauthorized administrative access to a Red Hat Satellite deployment, resulting in complete compromise of confidentiality, integrity, and availability of the managed infrastructure.
Apply patches available from the vendor according to the errata: RHSA-2024:6335 (Satellite 6.15), RHSA-2024:6336 (Satellite 6.14), RHSA-2024:6337 (Satellite 6.13), and RHSA-2024:8906. Details available at https://access.redhat.com/security/cve/CVE-2024-7012
Red Hat Satellite versions 6.13, 6.14, and 6.15 deployed with External Authentication and puppet-foreman configuration
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat Satellite
APPRedhat6.136.146.15
Related vulnerabilities
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
Authentication bypass w Pulpcore/Red Hat Satellite przez nagłówek HTTP
Arbitrary code execution w Foreman — obejście safe mode w szablonach
Eclipse OpenJ9: brak kontroli uprawnień do operacji diagnostycznych