Satellite
by Red Hat
Source repositories
CVEs (256)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-1832 | Med | 0.44 | 6.8 | 0.00 | Oct 4, 2023 | An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant. | ||
| CVE-2023-4886 | Med | 0.44 | 6.7 | 0.00 | Oct 3, 2023 | A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable. | ||
| CVE-2018-14666 | Med | 0.44 | 6.8 | 0.01 | Jan 22, 2019 | An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions. | ||
| CVE-2009-4139 | Med | 0.44 | 6.8 | 0.01 | Jul 27, 2011 | A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or… | ||
| CVE-2018-11212 | Med | 0.43 | 6.5 | 0.05 | May 16, 2018 | An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. | ||
| CVE-2018-2582 | Med | 0.43 | 6.5 | 0.05 | Jan 18, 2018 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access… | ||
| CVE-2020-14371 | Med | 0.42 | 6.5 | 0.01 | Jun 2, 2021 | A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite. | ||
| CVE-2020-10716 | Med | 0.42 | 6.5 | 0.01 | May 27, 2021 | A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This… | ||
| CVE-2014-3590 | Med | 0.42 | 6.5 | 0.01 | Jan 2, 2020 | Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content. | ||
| CVE-2013-6461 | Med | 0.42 | 6.5 | 0.02 | Nov 5, 2019 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits | ||
| CVE-2013-6460 | Med | 0.42 | 6.5 | 0.02 | Nov 5, 2019 | Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents | ||
| CVE-2019-10198 | Med | 0.42 | 6.5 | 0.02 | Jul 31, 2019 | An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through… | ||
| CVE-2018-1000632 | Hig | 0.42 | 7.5 | 0.07 | Aug 20, 2018 | dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker… | ||
| CVE-2017-7470 | Med | 0.42 | 6.5 | 0.02 | Jul 27, 2018 | It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py. | ||
| CVE-2017-2672 | Med | 0.42 | 6.5 | 0.01 | Jun 21, 2018 | A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems. | ||
| CVE-2016-1000338 | Hig | 0.42 | 7.5 | 0.02 | Jun 1, 2018 | In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the… | ||
| CVE-2018-1096 | Med | 0.42 | 6.5 | 0.01 | Apr 5, 2018 | An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database. | ||
| CVE-2017-10690 | Med | 0.42 | 6.5 | 0.01 | Feb 9, 2018 | In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4 | ||
| CVE-2014-8163 | Med | 0.42 | 6.5 | 0.02 | Aug 28, 2017 | Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5. | ||
| CVE-2017-10243 | Med | 0.42 | 6.5 | 0.03 | Aug 8, 2017 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows… |
- risk 0.44cvss 6.8epss 0.00
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
- risk 0.44cvss 6.7epss 0.00
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
- risk 0.44cvss 6.8epss 0.01
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
- risk 0.44cvss 6.8epss 0.01
A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote attacker to hijack the authentication of arbitrary users. This can lead to unauthorized actions, including disabling user accounts, adding new user accounts, or…
- risk 0.43cvss 6.5epss 0.05
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
- risk 0.43cvss 6.5epss 0.05
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access…
- risk 0.42cvss 6.5epss 0.01
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.
- risk 0.42cvss 6.5epss 0.01
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This…
- risk 0.42cvss 6.5epss 0.01
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content.
- risk 0.42cvss 6.5epss 0.02
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
- risk 0.42cvss 6.5epss 0.02
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
- risk 0.42cvss 6.5epss 0.02
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through…
- risk 0.42cvss 7.5epss 0.07
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker…
- risk 0.42cvss 6.5epss 0.02
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
- risk 0.42cvss 6.5epss 0.01
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
- risk 0.42cvss 7.5epss 0.02
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the…
- risk 0.42cvss 6.5epss 0.01
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
- risk 0.42cvss 6.5epss 0.01
In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4
- risk 0.42cvss 6.5epss 0.02
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
- risk 0.42cvss 6.5epss 0.03
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAX-WS). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows…
Page 5 of 13