在 foreman_ansible 插件的 Ansible 清单(inventory)API 中发现了缺陷。控制器在构建主机查询时,使用了未加作用域限制的 调用,该调用未强制执行与调用者 权限相关联的搜索过滤器。因此,一个其主机可见性受权限过滤器限制的已认证用户,可以在其组织内提供任意的主机 ID,并获取这些主机的完整 Ansible 清单信息,包括被标记为隐藏的参数字段值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | - |
cpe:/a:redhat:satellite:6
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86320 | 7.8 HIGH | Flatpak-builder: host code execution via `git am` hook execution in patch source extractio |
| CVE-2026-92904 | 4.3 MEDIUM | Rubygem-foreman_remote_execution: job output readable without object-level view_job_invoca |
| CVE-2026-92894 | 4.3 MEDIUM | Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value d |
No comments yet