Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107151— Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests

Quick assessment

Affected
Red Hat Red Hat Satellite 6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 smart_proxy_dynflow 包中,远程执行任务更新存在缺失身份验证的问题。当一次性令牌缺失时,系统仍会接受进度和完成回调报告。网络攻击者或用户必须已经知晓正在运行的作业的标识符。该问题适用于远程执行设置为拉取或拉取-MQTT 模式的情况。攻击者可以提交伪造的作业输出,并将作业标记为成功或失败,该结果随后会被记录到作业中。

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107151

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests
Source: CVE Program / CVE List V5
Vulnerability Description
Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6

II. Public POCs for CVE-2026-107151

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107151

请登录查看更多情报信息。

Other References for CVE-2026-107151 (2)

Same Patch Batch · Red Hat · 2026-10-07 · 13 CVEs total

CVE-2026-106471 8.1 HIGH Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult
CVE-2026-107121 6.5 MEDIUM Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg
CVE-2026-103869 6.5 MEDIUM Pulp-ansible: bearer tokens are reused across remotes in a worker
CVE-2026-103868 6.5 MEDIUM Pulp-container: registry credentials are reused across remotes in a worker
CVE-2026-107174 6.4 MEDIUM Source-to-image: source-to-image: security boundary bypass via absolute symbolic link extr
CVE-2026-106064 6.3 MEDIUM Gimp: gimp: heap buffer overflow in gif export on oversized image dimensions
CVE-2026-107169 6.2 MEDIUM M17n-lib: null-pointer write in read_mtext_element() on malformed utf-8
CVE-2026-107167 6.2 MEDIUM M17n-lib: heap use-after-free write in re_init_ic()
CVE-2026-107168 6.2 MEDIUM M17n-lib: parser infinite loop on malformed utf-8 in count_utf_8_chars()
CVE-2026-106061 5.5 MEDIUM Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file
CVE-2026-103870 5.0 MEDIUM Pulp-rpm: distribution tree publish creates directories from .treeinfo ids
CVE-2026-107170 2.9 LOW M17n-lib: null dereference in minput_open_im() after failed m17n_init()

IV. Related Vulnerabilities

V. Comments for CVE-2026-107151

No comments yet


Leave a comment