Impact
A flaw in the foreman_remote_execution plugin bypasses the view_job_invocations permission check during the show_template_invocation_by_host action, allowing an authenticated user to resolve any job invocation ID and read its live output, rendered script, and input values even when their visibility is normally restricted. This omission permits unauthorized disclosure of potentially sensitive job execution data within the user's organization. The vulnerability is a classic case of missing authorization (CWE-863), resulting in a breach of confidentiality rather than a denial of service or code execution.
Affected Systems
The affected product is Red Hat Satellite 6, specifically the foreman_remote_execution plugin. No specific affected version is listed; the issue applies to all builds that have not yet been patched by Red Hat’s security update for this CVE.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate threat severity. EPSS is not available, so the likelihood of exploitation is unclear, and the vulnerability is not currently listed in the CISA KEV catalog. A legitimate user with an account that has limited job invocation visibility can enumerate IDs and read other users’ job data, so the attack vector is an authenticated user within the same organization. Given the absence of a known workaround, the risk stems from insufficient access control rather than from any technical complexity or exploit code that is readily available.
OpenCVE Enrichment