https://seclists.org/oss-sec/2024/q3/252: CVE-2024-7012, CVE-2024-7923: Authentication bypass in Foman & Pulpco
Published Sep 6, 2024
·Updated
Affected Software
3 affected components
Pulp Pulpcore<22.0
Foreman Foreman>=3.10.1, >=3.11.2, >=3.12.0
Katello Katello>=4.0.0
Frequently Asked Questions
1
What is the severity of CVE-2024-7012?
CVE-2024-7012 is classified as a high severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2024-7923?
To resolve CVE-2024-7923, update Pulpcore and its dependencies to Gunicorn version 22.0 or later.
3
What systems are affected by CVE-2024-7012?
CVE-2024-7012 affects installations of Pulpcore when deployed using the Foreman Installer with certain configurations.
4
What impact does CVE-2024-7923 have on users?
CVE-2024-7923 can allow attackers to bypass authentication and gain unauthorized access to the system.
5
When was CVE-2024-7012 published?
CVE-2024-7012 was published on September 6, 2024.