End of life: 11/1/2027, End of support: 11/1/2026, Latest version: 6.19.3
End of life: 5/1/2027, End of support: 5/6/2026, Latest version: 6.18.7
A command injection flaw was found in Red Hat Satellite 6.16.5.2 (Foreman 3.12.0.8-1). Although a whitelist for CoreOS Transpiler Command and Fedora CoreOS Transpiler Command is implemented, the whitelist is only enforced on the client-side and is not validated on the server-side. This flaw allows an authenticated user with editsettings permissions to modify these parameters to achieve arbitrary command execution on underlying operating system and bypass safe mode rendering.
Important: Satellite 6.17.0 release
End of life: 11/30/2026, End of support: 11/30/2025, Latest version: 6.17.9
Important: Satellite 6.14.4.5 Async Update
Important: Satellite 6.15.5.2 Async Update
A flaw was found in Foreman / Red Hat Satellite, where temporary files created under /var/tmp during job execution have improper permissions. This allows low-privileged OS users to access and read command execution outputs, potentially exposing sensitive information such as system credentials or configuration details before the temporary files are deleted.This vulnerability does not grant direct privilege escalation but increases the risk of information disclosure, which could be leveraged in further attacks.
A flaw was found in Foreman / Red Hat Satellite, where temporary files created under /var/tmp during job execution have improper permissions. This allows low-privileged OS users to access and read command execution outputs, potentially exposing sensitive information such as system credentials or configuration details before the temporary files are deleted.This vulnerability does not grant direct privilege escalation but increases the risk of information disclosure, which could be leveraged in further attacks.
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. The problem described was inteded behavior and therefore not a bug.
End of life: 11/30/2025, End of support: 11/30/2024, Latest version: 6.15.5.8
End of life: 11/30/2025, End of support: 11/30/2024, Latest version: 6.15.5.8
Moderate: Satellite 6.15.5 Async Update
End of life: 5/31/2026, End of support: 5/31/2025, Latest version: 6.16.10
End of life: 5/31/2026, End of support: 5/31/2025, Latest version: 6.16.10
Important: Satellite 6.15.4.2 Async Update
Moderate: Satellite 6.15.4 Security Update
An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's modproxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 4.0+ and could potentially enable unauthorized users to gain administrative access.
An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's modproxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 4.0+ and could potentially enable unauthorized users to gain administrative access.
A command injection flaw was found in the "Host Init Config" template in the Foreman application via the "Install Packages" field on the "Register Host" page. This flaw allows an attacker with the necessary privileges to inject arbitrary commands into the configuration, potentially allowing unauthorized command execution during host registration. Although this issue requires user interaction to execute injected commands, it poses a significant risk if an unsuspecting user runs the generated registration script.
An authentication bypass vulnerability exists in Foreman due to Pulpcore when deployed with Gunicorn versions earlier than 22.0. The issue arises from how Apache’s modproxy handles header as it fails to unset it properly due to restrictions on underscores in HTTP headers. This allow authentication through malformed header instead. This flaw affects all Katello/Satellite 6.10+ deployments using Pulpcore from version 4.0+ and could potentially allow unauthorized users to gain admin access.
When running a remote execution job on a host, the ssh key of the host is not being checked. When the key changes, the Satellite connects it anyway because it uses "-o StrictHostKeyChecking=no". This can lead to MITM, DoS, leaking of whatever secrets the remote execution job contains, or whatever other issues may arise from the attacker being able to forge a ssh key. This does not directly allow unauthorized remote execution on the Satellite (although it can leak secrets leading to it)..
For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section.Security fixes: python-pygments: ReDoS in pygments (CVE-2022-40896) python-pycryptodomex: Side-channel leakage for OAEP decryption in PyCryptodome and pycryptodomex (CVE-2023-52323) satellite: Arithmetic overflow in satellite (CVE-2023-4320) automation-hub: Ansible Automation Hub: insecure galaxy-importer tarfile extraction (CVE-2023-5189) jetty: Improper addition of quotation marks to user inputs in CgiServlet (CVE-2023-36479) python-aiohttp: HTTP request smuggling via llhttp HTTP request parser (CVE-2023-37276) rubygem-activesupport: File Disclosure of Locally Encrypted Files (CVE-2023-38037) jetty: Improper validation of HTTP/1 content-length (CVE-2023-40167) python-django: Potential denial of service vulnerability in django.utils.encoding.uritoiri() (CVE-2023-41164) python-django: Denial-of-service possibility in django.utils.text.Truncator (CVE-2023-43665) python-aiohttp: Numerous issues in HTTP parser with header parsing (CVE-2023-47627) python-aiohttp: HTTP request modification (CVE-2023-49081) python-aiohttp: CRLF injection if user controls the HTTP method using aiohttp client (CVE-2023-49082) rubygem-puma: HTTP request smuggling when parsing chunked Transfer-Encoding Bodies (CVE-2024-21647) rubygem-audited: Race condition can lead to audit logs being incorrectly attributed to the wrong user (CVE-2024-22047) python-jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195) python-aiohttp: Followsymlinks directory traversal vulnerability (CVE-2024-23334) python-aiohttp: HTTP request smuggling (CVE-2024-23829) Additional Changes:This update also fixes several bugs and adds various enhancements.Documentation for these changes is available from the Release Notes document linked to in the References section.
A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the process list and allows an attacker to take advantage and obtain the password.
Moderate: Satellite 6.14.3 Async Security Update
Important: Satellite 6.14.2 Async Security Update
Moderate: Satellite 6.14.1 Async Security Update
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
An admin user on Foreman can bypass safe mode in templates and execute arbitrary code via the Report Templates function. When changing the "template" JSON value in the POST request, an attacker can exploit the bind() call in safemode to inject an OS command in the underlying operating system.
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.