Description

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) and could potentially enable unauthorized users to gain administrative access.

INFO

Published Date :

2024-09-04T13:41:17.877Z

Last Modified :

2025-11-11T15:29:25.711Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7012 vulnerability.

Vendors Products
Redhat
  • Satellite
  • Satellite Capsule
  • Satellite Maintenance
  • Satellite Utils

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact