Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-13316

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 4.4
EPSS Низкий

Описание

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*
Версия от 6.0 (включая) до 6.19 (включая)
Конфигурация 2
cpe:2.3:a:theforeman:foreman:-:*:*:*:*:*:*:*

EPSS

Процентиль: 1%
0.00105
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.4
redhat
2 месяца назад

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

CVSS3: 4.4
debian
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in ...

CVSS3: 4.4
github
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

EPSS

Процентиль: 1%
0.00105
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-918
Уязвимость CVE-2026-13316