Where
-Infinity
0
EOL
Nov 1, 2027
Support Ends
Nov 1, 2026

End of life: 11/1/2027, End of support: 11/1/2026, Latest version: 6.19.3

First published (updated )
EOL
May 1, 2027
Support Ends
May 6, 2026

End of life: 5/1/2027, End of support: 5/6/2026, Latest version: 6.18.7

First published (updated )
Severity
8
Command Injection, OS Command Injection
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

A command injection flaw was found in Red Hat Satellite 6.16.5.2 (Foreman 3.12.0.8-1). Although a whitelist for CoreOS Transpiler Command and Fedora CoreOS Transpiler Command is implemented, the whitelist is only enforced on the client-side and is not validated on the server-side. This flaw allows an authenticated user with editsettings permissions to modify these parameters to achieve arbitrary command execution on underlying operating system and bypass safe mode rendering.

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: Satellite 6.17.0 release

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index" target="_blank">https://docs.redhat.com/en/documentation/red_hat_satellite/6.17/html/updating_red_hat_satellite/index</a>
First published (updated )
EOL
Nov 30, 2026
Support Ends
Nov 30, 2025

End of life: 11/30/2026, End of support: 11/30/2025, Latest version: 6.17.9

First published (updated )
Severity
7

Important: Satellite 6.14.4.5 Async Update

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For detailed instructions how to apply this update, refer to:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.14/html/updating_red_hat_satellite/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.14/html/updating_red_hat_satellite/index</a>
First published (updated )
Severity
7

Important: Satellite 6.15.5.2 Async Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For detailed instructions how to apply this update, refer to:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index</a>
First published (updated )
Severity
3.3
AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A flaw was found in Foreman / Red Hat Satellite, where temporary files created under /var/tmp during job execution have improper permissions. This allows low-privileged OS users to access and read command execution outputs, potentially exposing sensitive information such as system credentials or configuration details before the temporary files are deleted.This vulnerability does not grant direct privilege escalation but increases the risk of information disclosure, which could be leveraged in further attacks.

1 / 2
Source: Red Hat
First published (updated )
Severity
1

A flaw was found in Foreman / Red Hat Satellite, where temporary files created under /var/tmp during job execution have improper permissions. This allows low-privileged OS users to access and read command execution outputs, potentially exposing sensitive information such as system credentials or configuration details before the temporary files are deleted.This vulnerability does not grant direct privilege escalation but increases the risk of information disclosure, which could be leveraged in further attacks.

First published (updated )
Severity
4
CSRF, SSRF

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described was inteded behavior and therefore not a bug.

1 / 2
Source: NVD
First published (updated )
EOL
Nov 30, 2025
Support Ends
Nov 30, 2024

End of life: 11/30/2025, End of support: 11/30/2024, Latest version: 6.15.5.8

First published (updated )
EOL
Nov 30, 2025
Support Ends
Nov 30, 2024

End of life: 11/30/2025, End of support: 11/30/2024, Latest version: 6.15.5.8

First published (updated )
Severity
4

Moderate: Satellite 6.15.5 Async Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For detailed instructions how to apply this update, refer to:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index</a>
First published (updated )
EOL
May 31, 2026
Support Ends
May 31, 2025

End of life: 5/31/2026, End of support: 5/31/2025, Latest version: 6.16.10

First published (updated )
EOL
May 31, 2026
Support Ends
May 31, 2025

End of life: 5/31/2026, End of support: 5/31/2025, Latest version: 6.16.10

First published (updated )
Severity
7

Important: Satellite 6.15.4.2 Async Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For detailed instructions how to apply this update, refer to:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index</a>
First published (updated )
Severity
4
Null Pointer Dereference

Moderate: Satellite 6.15.4 Security Update

1 / 2
Source: Red Hat

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For detailed instructions how to apply this update, refer to:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html/updating_red_hat_satellite/index</a>
First published (updated )
Severity
9.8
EPSS
0.07%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's modproxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 4.0+ and could potentially enable unauthorized users to gain administrative access.

1 / 2
Source: Red Hat
First published (updated )

An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's modproxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 4.0+ and could potentially enable unauthorized users to gain administrative access.

First published (updated )
Severity
6.5
EPSS
0.04%
Command Injection
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration, potentially allowing unauthorized command execution during host registration. Although this issue requires user interaction to execute injected commands, it poses a significant risk if an unsuspecting user runs the generated registration script.

1 / 2
Source: NVD
First published (updated )
Severity
9.8
EPSS
0.07%
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

An authentication bypass vulnerability exists in Foreman due to Pulpcore when deployed with Gunicorn versions earlier than 22.0. The issue arises from how Apache’s modproxy handles header as it fails to unset it properly due to restrictions on underscores in HTTP headers. This allow authentication through malformed header instead. This flaw affects all Katello/Satellite 6.10+ deployments using Pulpcore from version 4.0+ and could potentially allow unauthorized users to gain admin access.

1 / 2
Source: Red Hat
First published (updated )
Severity
4

When running a remote execution job on a host, the ssh key of the host is not being checked. When the key changes, the Satellite connects it anyway because it uses "-o StrictHostKeyChecking=no". This can lead to MITM, DoS, leaking of whatever secrets the remote execution job contains, or whatever other issues may arise from the attacker being able to forge a ssh key. This does not directly allow unauthorized remote execution on the Satellite (although it can leak secrets leading to it)..

First published (updated )
Severity
7
Race Condition, CRLF Injection

For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.Security fixes: python-pygments: ReDoS in pygments (CVE-2022-40896) python-pycryptodomex: Side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323) satellite: Arithmetic overflow in satellite (CVE-2023-4320) automation-hub: Ansible Automation Hub: insecure galaxy-importer tarfile extraction (CVE-2023-5189) jetty: Improper addition of quotation marks to user inputs in CgiServlet (CVE-2023-36479) python-aiohttp: HTTP request smuggling via llhttp HTTP request parser (CVE-2023-37276) rubygem-activesupport: File Disclosure of Locally Encrypted Files (CVE-2023-38037) jetty: Improper validation of HTTP/1 content-length (CVE-2023-40167) python-django: Potential denial of service vulnerability in django.utils.encoding.uritoiri() (CVE-2023-41164) python-django: Denial-of-service possibility in django.utils.text.Truncator (CVE-2023-43665) python-aiohttp: Numerous issues in HTTP parser with header parsing (CVE-2023-47627) python-aiohttp: HTTP request modification (CVE-2023-49081) python-aiohttp: CRLF injection if user controls the HTTP method using aiohttp client (CVE-2023-49082) rubygem-puma: HTTP request smuggling when parsing chunked Transfer-Encoding Bodies (CVE-2024-21647) rubygem-audited: Race condition can lead to audit logs being incorrectly attributed to the wrong user (CVE-2024-22047) python-jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195) python-aiohttp: Followsymlinks directory traversal vulnerability (CVE-2024-23334) python-aiohttp: HTTP request smuggling (CVE-2024-23829) Additional Changes:This update also fixes several bugs and adds various enhancements.Documentation for these changes is available from the Release Notes document linked to in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, refer to:<br><li> For upgrading connected Satellite: <a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html-single/upgrading_connected_red_hat_satellite_to_6.15" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html-single/upgrading_connected_red_hat_satellite_to_6.15</a></li> <li> For upgrading disconnected Satellite: <a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html-single/upgrading_disconnected_red_hat_satellite_to_6.15" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.15/html-single/upgrading_disconnected_red_hat_satellite_to_6.15</a></li>
First published (updated )
Severity
6.2
Infoleak
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.

1 / 2
Source: NVD
First published (updated )
Severity
4

Moderate: Satellite 6.14.3 Async Security Update

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For detailed instructions how to apply this update, refer to:<br><a href="https://access.redhat.com/documentation/en-us/red_hat_satellite/6.14/html/upgrading_and_updating_red_hat_satellite/index" target="_blank">https://access.redhat.com/documentation/en-us/red_hat_satellite/6.14/html/upgrading_and_updating_red_hat_satellite/index</a>
First published (updated )
Severity
7
Buffer Overflow

Important: Satellite 6.14.2 Async Security Update

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4
XSS

Moderate: Satellite 6.14.1 Async Security Update

Remedy

Before applying this update, make sure all previously released errata<br>relevant to your system have been applied.<br>For details on how to apply this update, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.

1 / 2
Source: MITRE
First published (updated )
Severity
9.1
OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

An admin user on Foreman can bypass safe mode in templates and execute arbitrary code via the Report Templates function. When changing the "template" JSON value in the POST request, an attacker can exploit the bind() call in safemode to inject an OS command in the underlying operating system.

1 / 2
Source: Red Hat
First published (updated )
Severity
5.4
XSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.

1 / 2
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203