Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13316

Опубликовано: 18 июн. 2026
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

Отчет

Red Hat Product Security has assessed that this issue is not exploitable under the default configuration. Exploitation requires an attacker with sufficient privileges on the host where Foreman is installed to modify the relevant configuration files and to trigger the Server-Side Request Forgery (SSRF) condition.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6foremanFix deferred
Red Hat Satellite 6satellite-utils:el8/foremanFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-918
https://bugzilla.redhat.com/show_bug.cgi?id=2490345Foreman: SSRF to cloud metada service through unvalidated test_url parameters in Foreman config

EPSS

Процентиль: 1%
0.00105
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

CVSS3: 4.4
debian
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in ...

CVSS3: 4.4
github
около 2 месяцев назад

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

EPSS

Процентиль: 1%
0.00105
Низкий

4.4 Medium

CVSS3