REDHAT-BUG-2547357: Medium severity Red Hat smart_proxy_dynflow vulnerability

Published Oct 7, 2026
·
Updated

Proxy::Dynflow::Api selects authorizewithtoken from the path alone. If the Authorization header is absent, that method returns false and does not halt. A Sinatra before filter ignores the return value, so POST /dynflow/tasks/<uuid>/update and /done reach dispatchexternalevent. A second bypass sits in the same check: OtpManager.authenticate treats a Basic token with no colon as otp = nil, and passwords[username] == nil is true when that task has no stored OTP. generateotp has no production caller on current smartproxyremoteexecutionssh 1.0.x. On 0.11.x it is called only by PollingScriptRunner, and only in async-SSH mode. Omitting the header still bypasses that case.

This does not launch jobs. In the default :ssh mode, Runner::Base#externalevent refreshes and drops the payload. In :pull and :'pull-mqtt', PullScript#processexternalevent stores the caller’s output and exitcode, and exit code 0 is recorded as success.

On Satellite 6.16–6.18, async-SSH PollingScriptRunner#externalevent can also apply the payload when manualmode is set. That runner was removed in smartproxyremoteexecutionssh 1.0.0 (commit d8d1811, 2025-11-28).

The attacker must already know a live execution-plan UUID. Step ids are small integers. The console flaw below is what gives those UUIDs to a host that holds a CA-signed certificate.

Likely to be introduced in smartproxydynflow 0.4.0 by commit e205e19.

Affected Software

3 affected components
Red Hat smart_proxy_dynflow>=0.4.0
Red Hat smart_proxy_remote_execution_ssh>=0.11.0<=0.11.x, >=1.0.0
Red Hat Satellite>=6.16<=6.18

Event History

Oct 7, 2026
Data Sourced
via Red Hat·10:20 AM
DescriptionSeverityAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203