Foreman 中存在一个缺陷:模板修订端点(template revision endpoint)在检索经过审计的模板修订记录时,未强制实施对象级授权。一个拥有模板相关权限(如 )的低权限认证用户,可以通过提供相应的审计 ID,获取属于其他组织或位置的历史模板内容。这可能导致未经授权披露历史模板内容,其中可能包含敏感的配置文件信息、凭据或其他机密信息。REST API 的修订端点对此查找操作有正确的限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-5680 | 7.5 HIGH | Undertow-core: undertow: denial of service via websocket permessage-deflate processing |
| CVE-2026-78002 | 7.5 HIGH | Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun |
| CVE-2026-81668 | 5.4 MEDIUM | Rubygem-katello: cross-tenant content view filter rule access and modification via unautho |
No comments yet