First published: Wed Oct 09 2024(Updated: )
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman | <3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6861 is classified as a high severity vulnerability due to the exposure of sensitive admin authentication keys.
To fix CVE-2024-6861, disable the GraphQL API introspection feature if it is enabled.
CVE-2024-6861 can lead to the disclosure of sensitive admin authentication keys.
CVE-2024-6861 affects versions of Foreman up to, but not including, 3.3.
The potential consequences of CVE-2024-6861 include a complete compromise of the product's API.