Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47859 | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API. |
Solution
No solution given by the vendor.
Workaround
To mitigate this issue the GraphQL introspection feature must be disabled or the GraphQL API be disabled entirely. Malicious requests can also be filtered using a reverse proxy or directly in the web server configuration.
Tue, 28 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:satellite:6 |
Thu, 09 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 06 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | foreman: foreman: OAuth secret exposure via unauthenticated access to the GraphQL API | Foreman: foreman: oauth secret exposure via unauthenticated access to the graphql api |
| First Time appeared |
Redhat satellite Maintenance
Redhat satellite Utils |
|
| CPEs | cpe:/a:redhat:satellite:6 cpe:/a:redhat:satellite_maintenance:6.12::el8 cpe:/a:redhat:satellite_utils:6.12::el8 |
|
| Vendors & Products |
Redhat satellite Maintenance
Redhat satellite Utils |
|
| References |
|
Thu, 10 Oct 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule |
|
| CPEs | cpe:/a:redhat:satellite:6.12::el8 cpe:/a:redhat:satellite_capsule:6.12::el8 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule |
Wed, 09 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API. | |
| Title | foreman: foreman: OAuth secret exposure via unauthenticated access to the GraphQL API | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-10-28T01:39:43.923Z
Reserved: 2024-07-17T20:36:00.703Z
Link: CVE-2024-6861
Updated: 2024-11-06T16:16:11.767Z
Status : Awaiting Analysis
Published: 2024-11-06T15:15:20.187
Modified: 2024-11-06T18:17:17.287
Link: CVE-2024-6861
OpenCVE Enrichment
No data.
EUVD