Описание
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.
Отчет
This vulnerability is rated Important for Red Hat Satellite due to an OS command injection flaw in the Foreman component. An authenticated user with edit_settings permissions can bypass client-side whitelisting for ct_location and fcct_location parameters, leading to arbitrary command execution on the underlying operating system. This affects Red Hat Satellite versions 6.15, 6.16, 6.17, and 6.18.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | satellite:el8/foreman | Affected | ||
| Red Hat Satellite 6.15 for RHEL 8 | foreman | Fixed | RHSA-2025:19856 | 06.11.2025 |
| Red Hat Satellite 6.16 for RHEL 8 | foreman | Fixed | RHSA-2025:19855 | 06.11.2025 |
| Red Hat Satellite 6.16 for RHEL 9 | foreman | Fixed | RHSA-2025:19855 | 06.11.2025 |
| Red Hat Satellite 6.17 for RHEL 9 | foreman | Fixed | RHSA-2025:19832 | 05.11.2025 |
| Red Hat Satellite 6.18 for RHEL 9 | foreman | Fixed | RHSA-2025:19721 | 04.11.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
8 High
CVSS3
Связанные уязвимости
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.
EPSS
8 High
CVSS3