在 Foreman 中发现了一个安全漏洞。该漏洞允许拥有低级别 Viewer(查看者)权限的已认证用户,通过向模板预览端点提交请求,导致未经授权的敏感信息泄露。利用此漏洞,攻击者可以访问诸如主机 root 密码等敏感数据。此外,在系统配置不安全且 Safemode(安全模式)保护被禁用的情况下,该漏洞还可能允许攻击者以 Foreman 系统账户身份执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.23-1.el8sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.23-1.el9sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.22-1.el9sat< * |
unaffected |
0:3.2.13-1.el9pc< * |
unaffected | ||
0:3.1.62-1.el9pc< * |
unaffected | ||
0:5.3.1-2.el9pc< * |
unaffected | ||
0:0.6.0-1.el9pc< * |
unaffected | ||
0:15.0.2-2.el9sat< * |
unaffected | ||
0:3.14.0-2.el9sat< * |
unaffected | ||
0:4.16.0.20-1.el9sat< * |
unaffected | ||
| … +3 more rows | |||
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.25-1.el9sat< * |
unaffected |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0.14-1.el9sat< * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.23-1.el8sat ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.23-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.16::el8
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.22-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.2.13-1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.1.62-1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:5.3.1-2.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.6.0-1.el9pc ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:15.0.2-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.16.0.20-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.5.0-2.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:6.17.12-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.1.0-2.1.el9sat ~ * |
cpe:/a:redhat:satellite:6.17::el9
|
|
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.25-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.18::el9
|
|
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0.14-1.el9sat ~ * |
cpe:/a:redhat:satellite:6.19::el9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96658 | 9.9 CRITICAL | Foreman: safemode bypass leading to rce |
| CVE-2026-86345 | 9.0 CRITICAL | 389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to f |
| CVE-2026-12405 | 8.8 HIGH | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user |
| CVE-2026-12540 | 8.2 HIGH | Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter |
| CVE-2026-12541 | 8.2 HIGH | Foreman: command injection in foreman-rake database tasks |
| CVE-2026-12544 | 7.7 HIGH | Foreman: ssti and insecure deserialization in foreman-rake configuration |
| CVE-2026-86344 | 7.5 HIGH | 389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-oper |
| CVE-2026-12423 | 7.5 HIGH | Foreman: unauthenticated information disclosure via provisioning token validation flaw |
| CVE-2026-96577 | 7.1 HIGH | Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without a |
| CVE-2026-12545 | 6.7 MEDIUM | Rubygem-hammer_cli: command injection via insecure editor invocation |
| CVE-2026-56097 | 6.5 MEDIUM | Rubygem-katello: sql injection in registry proxy via labels |
| CVE-2026-103884 | 6.5 MEDIUM | Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allow |
| CVE-2026-83589 | 6.1 MEDIUM | Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect |
| CVE-2026-103754 | 5.9 MEDIUM | Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows |
| CVE-2026-103641 | 5.5 MEDIUM | Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder |
| CVE-2026-12542 | 5.3 MEDIUM | Foreman: command injection in foreman-tail |
| CVE-2026-56098 | 4.3 MEDIUM | Rubygem-katello: improper authorization logic allows resource enumeration |
No comments yet