Redhat

Satellite

261 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 07.10.2026 12:36:29
  • Zuletzt bearbeitet 07.10.2026 14:47:21

Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the iden...

  • EPSS 0.23%
  • Veröffentlicht 07.10.2026 05:46:18
  • Zuletzt bearbeitet 07.10.2026 20:17:07

A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area ...

  • EPSS 0.28%
  • Veröffentlicht 07.10.2026 02:16:57
  • Zuletzt bearbeitet 07.10.2026 17:16:48

A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacke...

  • EPSS 0.31%
  • Veröffentlicht 01.10.2026 17:14:56
  • Zuletzt bearbeitet 07.10.2026 07:17:01

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and...

  • EPSS 0.55%
  • Veröffentlicht 01.10.2026 17:14:49
  • Zuletzt bearbeitet 07.10.2026 07:17:00

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval...

  • EPSS 0.51%
  • Veröffentlicht 01.10.2026 17:14:49
  • Zuletzt bearbeitet 07.10.2026 07:17:00

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby s...

  • EPSS 0.7%
  • Veröffentlicht 01.10.2026 16:23:23
  • Zuletzt bearbeitet 07.10.2026 07:17:02

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can a...

Medienbericht
  • EPSS 0.32%
  • Veröffentlicht 01.10.2026 16:23:23
  • Zuletzt bearbeitet 07.10.2026 07:17:02

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can a...

  • EPSS 0.22%
  • Veröffentlicht 01.10.2026 16:22:15
  • Zuletzt bearbeitet 07.10.2026 07:17:00

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage ex...

  • EPSS 1.31%
  • Veröffentlicht 01.10.2026 16:22:09
  • Zuletzt bearbeitet 07.10.2026 07:17:00

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file pa...