GHSA-6m3j-qcjr-3vqmHighCVSS 7.5
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is...
🔗 CVE IDs covered (1)
📋 Description
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-12423
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/security/cve/CVE-2026-12423
- https://bugzilla.redhat.com/show_bug.cgi?id=2488956
- https://access.redhat.com/errata/RHSA-2026:74504
- https://access.redhat.com/errata/RHSA-2026:74506
- https://access.redhat.com/errata/RHSA-2026:74505
- https://github.com/advisories/GHSA-6m3j-qcjr-3vqm