Impact
An authentication bypass flaw exists in Foreman’s host provisioning API. The server checks a provisioning token’s database state rather than its presence in the HTTP request. When a host is actively provisioning and has an unexpired token stored in the database, the valid_host_token? method returns true even if the requester supplies no token. An attacker can therefore access the kickstart template and other provisioning data without authenticating.
Affected Systems
Red Hat Satellite 6 and the 6.19 release for RHEL 9 are affected, as indicated by the CNA vendor product list. These products rely on the Foreman provisioning API endpoint /unattended/provision.
Risk and Exploitability
The CVSS score of 7.5 signals a high severity vulnerability. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an unauthenticated request to the /unattended/provision endpoint while a host is in provisioning. The vulnerability requires the host to be actively provisioning with an unexpired token stored in the database, which may limit its exploitability in some environments.
OpenCVE Enrichment