CVE-2026-107151: fallo de gravedad media en Red Hat Satellite 6
Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.9
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Productos afectados
Red Hat · Red Hat Satellite 6CVEs relacionadas — Red Hat Satellite 6
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-3874HIGHOs command injection via ct_command and fcct_commandEPSS 2.2%CVE-2026-12405HIGHRubygem-foreman_remote_execution: command injection in job invocations via effective_user parameterEPSS 1.5%CVE-2026-1961HIGHForman: foreman: remote code execution via command injection in websocket proxyEPSS 1.4%CVE-2026-12541HIGHForeman: command injection in foreman-rake database tasksEPSS 1.3%CVE-2026-12540HIGHForeman: command injection in foreman-rake errors:fetch_log via request_id parameterEPSS 1.3%CVE-2024-11831MEDIUMNpm-serialize-javascript: cross-site scripting (xss) in serialize-javascriptEPSS 1.1%