REDHAT-BUG-2490345: SSRF
Published Jun 18, 2026
·Updated
A flaw has been found in foreman when HTTP parameters are modified in httpproxiescontroller and httpproxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Affected Software
1 affected component
Foreman
Event History
Jun 18, 2026
Data Sourced
via Red Hat·03:07 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2490345?
The severity of REDHAT-BUG-2490345 is medium, rated at 4.
2
What kind of attack does REDHAT-BUG-2490345 allow?
REDHAT-BUG-2490345 allows attackers to perform a Server-Side Request Forgery (SSRF) attack.
3
How can REDHAT-BUG-2490345 affect cloud environments?
REDHAT-BUG-2490345 can lead to unauthorized access to cloud metadata services on AWS, GCP, or Azure.
4
What component of the software is impacted by REDHAT-BUG-2490345?
The affected component in REDHAT-BUG-2490345 is the Foreman application.
5
How do I remediate REDHAT-BUG-2490345?
To remediate REDHAT-BUG-2490345, update the Foreman software to the latest version where the vulnerability is patched.