Описание
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Satellite 6 | satellite-capsule:el8/foreman | Affected | ||
| Red Hat Satellite 6.16 for RHEL 8 | foreman | Fixed | RHSA-2026:34367 | 01.07.2026 |
| Red Hat Satellite 6.16 for RHEL 9 | foreman | Fixed | RHSA-2026:34367 | 01.07.2026 |
| Red Hat Satellite 6.17 for RHEL 9 | foreman | Fixed | RHSA-2026:34366 | 01.07.2026 |
| Red Hat Satellite 6.18 for RHEL 9 | foreman | Fixed | RHSA-2026:34368 | 01.07.2026 |
| Red Hat Satellite 6.19 for RHEL 9 | foreman | Fixed | RHSA-2026:34365 | 01.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
A flaw was found in foreman. Authenticated users with 'view_keypairs' ...
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
EPSS
6.5 Medium
CVSS3