n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 10
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Theforeman Foreman
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*
|
1.22.0
|
3.16.2
|
|
Redhat Satellite
cpe:2.3:a:redhat:satellite:6.15:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite
cpe:2.3:a:redhat:satellite:6.16:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite
cpe:2.3:a:redhat:satellite:6.17:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite
cpe:2.3:a:redhat:satellite:6.18:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite_Capsule
cpe:2.3:a:redhat:satellite_capsule:6.15:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite_Capsule
cpe:2.3:a:redhat:satellite_capsule:6.16:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite_Capsule
cpe:2.3:a:redhat:satellite_capsule:6.17:*:*:*:*:*:*:*
|
— | — |
|
Redhat Satellite_Capsule
cpe:2.3:a:redhat:satellite_capsule:6.18:*:*:*:*:*:*:*
|
— | — |
|
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
|
— | — |