Impact
A missing authentication check in the smart_proxy_dynflow task callbacks allows an attacker to submit a job completion report without providing the required one‑time token. The vulnerability can be abused to mark a running remote execution job as succeeded or failed, thereby altering the recorded job outcome. This flaw is rooted in CWE‑306, improper authorization.
Affected Systems
The flaw affects Red Hat Satellite 6, specifically the smart_proxy_dynflow component. No specific sub‑versions are listed, so all currently installed instances of Satellite 6 are assumed vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet confirmed. Attackers would need to know the identifier of a running job and be able to reach the callback endpoint over the network. Once these prerequisites are satisfied, they can send crafted HTTP requests to change job status. The risk is therefore moderate with potential impact on the integrity of job reporting and downstream automation that relies on accurate job outcomes.
OpenCVE Enrichment