Vulnerabilities
Vulnerable Software
Redhat:  >> Satellite  >> 6.11  Security Vulnerabilities
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
CVSS Score
4.4
EPSS Score
0.001
Published
2026-06-30
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.
CVSS Score
7.6
EPSS Score
0.005
Published
2023-12-18
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
CVSS Score
8.0
EPSS Score
0.01
Published
2023-09-20
A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.
CVSS Score
4.5
EPSS Score
0.007
Published
2022-12-16


Contact Us

Shodan ® - All rights reserved