Redhat

Satellite

261 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.31%
  • Veröffentlicht 01.10.2026 16:22:02
  • Zuletzt bearbeitet 07.10.2026 07:17:00

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task...

  • EPSS 1.5%
  • Veröffentlicht 01.10.2026 16:21:44
  • Zuletzt bearbeitet 07.10.2026 07:16:59

A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fa...

  • EPSS 0.25%
  • Veröffentlicht 17.09.2026 12:42:57
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against th...

  • EPSS 0.28%
  • Veröffentlicht 17.09.2026 10:28:12
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticate...

  • EPSS 0.26%
  • Veröffentlicht 17.09.2026 10:17:06
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user w...

  • EPSS 0.88%
  • Veröffentlicht 01.09.2026 13:20:27
  • Zuletzt bearbeitet 02.09.2026 09:16:39

A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolok...

  • EPSS 0.14%
  • Veröffentlicht 27.08.2026 11:15:42
  • Zuletzt bearbeitet 28.08.2026 21:17:10

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to acce...

  • EPSS 0.21%
  • Veröffentlicht 27.08.2026 10:22:08
  • Zuletzt bearbeitet 07.10.2026 15:25:07

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can ...

  • EPSS 0.33%
  • Veröffentlicht 26.08.2026 05:37:38
  • Zuletzt bearbeitet 02.10.2026 18:17:05

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to...

  • EPSS 0.32%
  • Veröffentlicht 21.07.2026 17:26:14
  • Zuletzt bearbeitet 04.09.2026 03:17:41

A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections...