Описание
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.
Отчет
This vulnerability was reported for an End of Life Product and does not affect any current supported Red Hat Products. The fix was included in foreman version 3.3 which was first shipped in Satellite 6.12.
Меры по смягчению последствий
To mitigate this issue the GraphQL introspection feature must be disabled or the GraphQL API be disabled entirely. Malicious requests can also be filtered using a reverse proxy or directly in the web server configuration.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | satellite-capsule:el8/foreman | Not affected | ||
| Red Hat Satellite 6 | satellite:el8/foreman | Not affected | ||
| Red Hat Satellite 6 | satellite-utils:el8/foreman | Not affected | ||
| Red Hat Satellite 6.12 for RHEL 8 | foreman | Fixed | RHSA-2022:8506 | 16.11.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.
A disclosure of sensitive information flaw was found in foreman via th ...
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.
EPSS
7.5 High
CVSS3