An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 3.0+ and could potentially enable unauthorized users to gain administrative access.
The problem results from improper Apache mod_proxy configuration, which does not properly remove HTTP headers containing underscore characters. The puppet-pulpcore configuration combined with Gunicorn below version 22.0 allows an attacker to send a specially crafted malformed HTTP header that passes through the proxy layer without sanitization. Pulpcore's authentication mechanism incorrectly interprets such a header as identity confirmation, enabling the authentication verification process to be bypassed (CWE-287).
An unauthenticated remote attacker can gain full administrative access to the Red Hat Satellite system, leading to complete loss of confidentiality, integrity, and availability of managed infrastructure.
Patches available from the vendor should be applied according to references: RHSA-2024:6335 (Satellite 6.15), RHSA-2024:6336 (Satellite 6.14), RHSA-2024:6337 (Satellite 6.13), and RHSA-2024:8906. It is critical to update Gunicorn to version 22.0 or later as part of the Satellite update.
Red Hat Satellite 6.13, 6.14, and 6.15 with Pulpcore version 3.0 or later, deployed with Gunicorn version below 22.0
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRed Hat Satellite
APPRedhat6.136.146.15
Related vulnerabilities
Krytyczna podatność RCE w Oracle Java SE i JRockit — komponent JMX
Krytyczna podatność RCE w Oracle Java SE — komponent Libraries
Authentication Bypass w Foreman/Red Hat Satellite via zniekształcony nagłówek HTTP
Arbitrary code execution w Foreman — obejście safe mode w szablonach
Eclipse OpenJ9: brak kontroli uprawnień do operacji diagnostycznych