Impact
The vulnerability resides in Foreman. Authenticated users who possess the 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH keys belonging to other tenants by supplying a key‑pair identifier. This control flaw, a CWE‑639 information‑disclosure by‑tenant exposure of confidential credentials.
Affected Systems
Red Hat Satellite 6, including the base release and the 6.16 release for RHEL 8 and for RHEL 9, plus the 6.17, 6.18, and 6.19 releases for RHEL 9, is affected. Satellite Capsule, Satellite Maintenance, and Satellite Utils components for the corresponding version numbers are also impacted. Any installation of these specific product versions remains vulnerable until an update that addresses the issue is applied.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity. Exploitation requires an authenticated account with the view_keypairs permission, limiting the attack surface to privileged or compromised users. The EPSS score of < 1% and absence from the CISA KEV catalog indicate a low likelihood of widespread exploitation. Nonetheless, once the required permissions are present, an attacker can retrieve any private SSH key by providing its identifier, resulting in immediate confidentiality loss across tenant boundaries.
OpenCVE Enrichment