Impact
An authenticated user with host‑edit permissions can exploit a flaw in Red Hat Satellite’s Foreman component. The issue is a CWE‑639 weakness where the taxonomy_scope controller does not validate nested organization and location identifiers, allowing the user to bypass existing authorization checks. As a result, the attacker can disclose sensitive infrastructure metadata—such as subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs—from organizations and locations that the user is not authorized to access.
Affected Systems
The vulnerability affects Red Hat Satellite 6 and its newer releases, including Satellite 6.16 for RHEL 8, Satellite 6.16–6.19 for RHEL 9, and associated capsule, maintenance, and utilities components. All installations that incorporate the Foreman component without the latest updates are susceptible.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as moderate, and the EPSS score of < 1 % indicates a very low probability of exploitation. It is not listed in CISA’s KEV catalog. The attack requires an authenticated user with host‑edit permissions to send requests that contain nested organization and location identifiers that the system accepts even when the user is not authorized to access those resources.
OpenCVE Enrichment