CRITICAL🇵🇱 Wersja polska

CVE-2024-7923

CVSS 9.8v3.1pub. 2024-09-04upd. 2024-11-24

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 3.0+ and could potentially enable unauthorized users to gain administrative access.

🤖 AI Analysis
How it works

The problem results from improper Apache mod_proxy configuration, which does not properly remove HTTP headers containing underscore characters. The puppet-pulpcore configuration combined with Gunicorn below version 22.0 allows an attacker to send a specially crafted malformed HTTP header that passes through the proxy layer without sanitization. Pulpcore's authentication mechanism incorrectly interprets such a header as identity confirmation, enabling the authentication verification process to be bypassed (CWE-287).

Impact

An unauthenticated remote attacker can gain full administrative access to the Red Hat Satellite system, leading to complete loss of confidentiality, integrity, and availability of managed infrastructure.

Mitigation & patch

Patches available from the vendor should be applied according to references: RHSA-2024:6335 (Satellite 6.15), RHSA-2024:6336 (Satellite 6.14), RHSA-2024:6337 (Satellite 6.13), and RHSA-2024:8906. It is critical to update Gunicorn to version 22.0 or later as part of the Satellite update.

Who is affected

Red Hat Satellite 6.13, 6.14, and 6.15 with Pulpcore version 3.0 or later, deployed with Gunicorn version below 22.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Red Hat Satellite

    APP
    Redhat
    6.136.146.15
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2016-3427CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX

CVE-2015-2590CRITICAL9.8⚠ KEVPL ✓same product

Krytyczna podatność RCE w Oracle Java SE — komponent Libraries

CVE-2024-7012CRITICAL9.8PL ✓same product

Authentication Bypass w Foreman/Red Hat Satellite via zniekształcony nagłówek HTTP

CVE-2023-0118CRITICAL9.1PL ✓same product

Arbitrary code execution w Foreman — obejście safe mode w szablonach

CVE-2019-17631CRITICAL9.1PL ✓same product

Eclipse OpenJ9: brak kontroli uprawnień do operacji diagnostycznych