CVE-2026-107151mediumCWE-306

CVE-2026-107151: fallo de gravedad media en Red Hat Satellite 6

Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests

Publicada el

10Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.9
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N