Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5142

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6satellite-capsule:el8/foremanAffected
Red Hat Satellite 6.16 for RHEL 8foremanFixedRHSA-2026:3436701.07.2026
Red Hat Satellite 6.16 for RHEL 9foremanFixedRHSA-2026:3436701.07.2026
Red Hat Satellite 6.17 for RHEL 9foremanFixedRHSA-2026:3436601.07.2026
Red Hat Satellite 6.18 for RHEL 9foremanFixedRHSA-2026:3436801.07.2026
Red Hat Satellite 6.19 for RHEL 9foremanFixedRHSA-2026:3436501.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2452999foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass

EPSS

Процентиль: 20%
0.00278
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

CVSS3: 6.5
debian
около 1 месяца назад

A flaw was found in foreman. Authenticated users with 'view_keypairs' ...

CVSS3: 6.5
github
около 1 месяца назад

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

EPSS

Процентиль: 20%
0.00278
Низкий

6.5 Medium

CVSS3