Impact
The foreman_ansible plugin’s Ansible inventory API contains an authorization flaw: the query that retrieves host data calls an unscoped Host.where without enforcing the caller’s view_hosts permission filter. As a result, any authenticated user who has permission to view hosts can request arbitrary host IDs within their organization and receive the full inventory for those hosts, including parameter values that are normally hidden. This flaw is a classic example of missing authorization (CWE-863) and allows direct exposure of sensitive configuration information without requiring additional privileges.
Affected Systems
Red Hat Satellite 6 installations that have the foreman_ansible plugin installed are affected. The specific Satellite minor or plugin release numbers are not provided in the data, so all versions with the flaw should be considered vulnerable.
Risk and Exploitability
The vulnerability receives a CVSS Base score of 4.3, indicating lower‑to‑moderate severity. An EPSS score is not available, so exploit probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known large‑scale exploitation. Based on the description, it is inferred that the attack vector requires authenticated access with a view_hosts role. Once that prerequisite is satisfied, the bug bypasses host visibility enforcement, allowing the attacker to read hidden parameters for any host within the organization, potentially exposing high‑value credentials.
OpenCVE Enrichment