Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-6861

Опубликовано: 09 окт. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

Отчет

This vulnerability was reported for an End of Life Product and does not affect any current supported Red Hat Products. The fix was included in foreman version 3.3 which was first shipped in Satellite 6.12.

Меры по смягчению последствий

To mitigate this issue the GraphQL introspection feature must be disabled or the GraphQL API be disabled entirely. Malicious requests can also be filtered using a reverse proxy or directly in the web server configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6satellite-capsule:el8/foremanNot affected
Red Hat Satellite 6satellite:el8/foremanNot affected
Red Hat Satellite 6satellite-utils:el8/foremanNot affected
Red Hat Satellite 6.12 for RHEL 8foremanFixedRHSA-2022:850616.11.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2317450foreman: foreman: OAuth secret exposure via unauthenticated access to the GraphQL API

EPSS

Процентиль: 52%
0.00292
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

CVSS3: 7.5
debian
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via th ...

CVSS3: 7.5
github
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

EPSS

Процентиль: 52%
0.00292
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-6861