Foreman是Foreman开源的一套用于物理和虚拟服务器中的生命周期管理工具。该工具提供服务开通、配置管理以及报告状态等功能。 Foreman存在安全漏洞,该漏洞源于WebSocket代理实现中的命令注入,当系统使用来自计算资源提供商的未清理主机名值构建shell命令时,攻击者通过操作恶意计算资源服务器,在用户访问VM VNC控制台功能时可能在Foreman服务器上实现远程代码执行,从而可能导致敏感凭据和整个托管基础设施被破解。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | 全部 |
affected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.14-1.el8sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.14-1.el9sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.14-1.el9sat< * |
unaffected |
0:0.1.23-0.3.el9pc< * |
unaffected | ||
0:1.2.0-0.1.el9pc< * |
unaffected | ||
0:4.2.28-0.1.el9pc< * |
unaffected | ||
0:2.22.3-1.el9pc< * |
unaffected | ||
0:3.27.10-2.el9pc< * |
unaffected | ||
0:1.5.1-1.el9sat< * |
unaffected | ||
0:0.4.3-1.el9sat< * |
unaffected | ||
| … +16 条更多 | |||
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.12-1.el9sat< * |
unaffected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.14-1.el8sat ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.14-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.14-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.1.23-0.3.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.2.0-0.1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.2.28-0.1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:2.22.3-1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.27.10-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.5.1-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.4.3-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.16.0.14-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.13.0-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:6.17.7-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.0.3-4.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.14-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.1.23-0.3.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.2.0-0.1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.2.28-0.1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:2.22.3-1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.27.10-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.5.1-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.4.3-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.16.0.14-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.13.0-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:6.17.7-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.0.3-4.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.12-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.18::el9
|
|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2025-12805 | 8.1 HIGH | Llama Stack 安全漏洞 |
| CVE-2026-2436 | 6.5 MEDIUM | libsoup 安全漏洞 |
| CVE-2026-3121 | 6.5 MEDIUM | Keycloak 安全漏洞 |
| CVE-2026-4887 | 6.1 MEDIUM | Red Hat Enterprise Linux 安全漏洞 |
| CVE-2026-4897 | 5.5 MEDIUM | polkit 安全漏洞 |
| CVE-2026-2272 | 4.3 MEDIUM | GIMP 安全漏洞 |
| CVE-2026-3190 | 4.3 MEDIUM | Keycloak 安全漏洞 |
| CVE-2026-2271 | 3.3 LOW | GIMP 安全漏洞 |
| CVE-2026-0968 | 3.1 LOW | libssh 安全漏洞 |
| CVE-2026-4874 | 3.1 LOW | Keycloak 代码问题漏洞 |
| CVE-2026-2239 | 2.8 LOW | GIMP 安全漏洞 |
| CVE-2026-0965 | libssh 安全漏洞 | |
| CVE-2026-0967 | libssh 安全漏洞 | |
| CVE-2026-0964 | libssh 安全漏洞 | |
| CVE-2026-0966 | libssh 安全漏洞 |
暂无评论