The Foreman foreman-mcp-server是The Foreman组织的一个连接Foreman基础设施管理平台的MCP服务器。 The Foreman foreman-mcp-server存在信息泄露漏洞,该漏洞源于foreman-mcp-server组件使用两种不同的日志记录机制,可能泄露敏感会话和身份验证数据,一种机制在信息级别记录会话标识符,另一种在启用调试日志时未完全清理HTTP请求标头,导致授权令牌和API密钥等敏感信息以明文形式记录,攻击者可利用此漏洞导致机密性泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6.18 | 1782228427< * |
unaffected |
| Red Hat | Red Hat Satellite 6.19 | 1782228692< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6.18 | 1782228427 ~ * |
cpe:/a:redhat:satellite:6.18::el9
|
|
| Red Hat | Red Hat Satellite 6.19 | 1782228692 ~ * |
cpe:/a:redhat:satellite:6.19::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11807 | 9.6 CRITICAL | Eda-server: websocket missing authorization allows credential theft via activation_id spoo |
| CVE-2026-12112 | 7.8 HIGH | Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse |
| CVE-2026-10609 | 6.8 MEDIUM | Openshift/cluster-logging-operator: cluster logging operator creates and forwards servicea |
| CVE-2026-11820 | 6.5 MEDIUM | Community.general: community.general nexmo — api credentials exposed in get url query stri |
| CVE-2026-11819 | 5.5 MEDIUM | Community.general: community.general keyring_info — os keyring passphrase returned in plai |
| CVE-2026-12969 | 5.3 MEDIUM | Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation |
| CVE-2026-55655 | 5.0 MEDIUM | Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat ente |
| CVE-2026-12892 | 4.4 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.2 |
| CVE-2026-55653 | 4.3 MEDIUM | Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path du |
| CVE-2026-12891 | 4.3 MEDIUM | Gstreamer1-plugins-bad-free: gstreamer1-plugins-bad: global buffer overflow (oob read) in |
| CVE-2026-55654 | 3.7 LOW | Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi in |
No comments yet