Advisory Published
Updated

REDHAT-BUG-2299429

First published: Tue Jul 23 2024(Updated: )

An authentication bypass vulnerability exists in Foreman due to Pulpcore when deployed with Gunicorn versions earlier than 22.0. The issue arises from how Apache’s mod_proxy handles header as it fails to unset it properly due to restrictions on underscores in HTTP headers. This allow authentication through malformed header instead. This flaw affects all Katello/Satellite 6.10+ deployments using Pulpcore from version 4.0+ and could potentially allow unauthorized users to gain admin access.

Affected SoftwareAffected VersionHow to fix
Gunicorn<22.0
>=4.0
>=6.10
Red Hat Network Satellite Server>=6.10

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-2299429?

    The severity of REDHAT-BUG-2299429 is classified as a high-risk vulnerability due to the authentication bypass it causes.

  • How do I fix REDHAT-BUG-2299429?

    To fix REDHAT-BUG-2299429, upgrade Gunicorn to version 22.0 or later, and ensure that your deployment of Pulpcore is updated accordingly.

  • Which versions of Gunicorn are affected by REDHAT-BUG-2299429?

    Gunicorn versions earlier than 22.0 are affected by REDHAT-BUG-2299429.

  • What software is related to REDHAT-BUG-2299429?

    REDHAT-BUG-2299429 impacts Gunicorn, Pulpcore, Red Hat Katello, and Red Hat Satellite versions specified.

  • Is there a workaround for REDHAT-BUG-2299429?

    Currently, the best practice is to upgrade to the latest versions of the affected software rather than relying on a workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203