REDHAT-BUG-1969265: Medium severity foreman vulnerability
An attacker with elevated privileges can utilize Ansible functions to carry out actions as the Foreman-proxy user on the system. The prerequisite for this is that the hosts must have already been added to Foreman, and the attacker must have access to one of these hosts. If the attacker already has access to the system, they are deemed trustworthy with a high level of privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1969265?
The severity of REDHAT-BUG-1969265 is critical due to the potential for unauthorized privilege escalation.
How do I fix REDHAT-BUG-1969265?
To fix REDHAT-BUG-1969265, ensure that your Foreman installation is updated to the latest patched version provided by Red Hat.
Who is affected by REDHAT-BUG-1969265?
Systems running Red Hat Foreman that have hosts added and are accessible by an attacker with elevated privileges are affected by REDHAT-BUG-1969265.
What can an attacker do with REDHAT-BUG-1969265?
An attacker exploiting REDHAT-BUG-1969265 can execute commands as the Foreman-proxy user, potentially compromising the system.
What are the prerequisites for exploiting REDHAT-BUG-1969265?
The prerequisites for exploiting REDHAT-BUG-1969265 include having elevated privileges and access to a host already added to Foreman.