CVE-2019-10198
published 2019-07-31CVE-2019-10198: An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.60%
72.9th percentile
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| the_foreman_project | foreman-tasks | — | — |
| theforeman | foreman-tasks | < 0.15.7 | 0.15.7 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
foreman: authorization bypasses in foreman-tasks leading to information disclosure
vendor_redhat·2019-07-12·CVSS 6.5
CVE-2019-10198 [MEDIUM] CWE-287 foreman: authorization bypasses in foreman-tasks leading to information disclosure
foreman: authorization bypasses in foreman-tasks leading to information disclosure
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
An authentication bypass vulnerability was discovered in Foreman. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
GHSA
GHSA-gq5x-r3g9-ch4f: An authentication bypass vulnerability was discovered in foreman-tasks before 0
ghsa_unreviewed·2022-05-24
CVE-2019-10198 [MEDIUM] CWE-306 GHSA-gq5x-r3g9-ch4f: An authentication bypass vulnerability was discovered in foreman-tasks before 0
An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.
No detection rules found.
No public exploits indexed.
2019-07-31
Published