CVE-2019-10198DEPRECATED: Authentication Bypass Issues in Foreman-tasks

Severity
6.5MEDIUMNVD
EPSS
1.4%
top 19.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 31
Latest updateMay 24

Description

An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an unauthenticated user can view the details of a task through the web UI or API, if they can discover or guess the UUID of the task.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gq5x-r3g9-ch4f: An authentication bypass vulnerability was discovered in foreman-tasks before 02022-05-24
CVEList
CVE-2019-10198: An authentication bypass vulnerability was discovered in foreman-tasks before 02019-07-31

📋Vendor Advisories

1
Red Hat
foreman: authorization bypasses in foreman-tasks leading to information disclosure2019-07-12

💬Community

1
Bugzilla
CVE-2019-10198 foreman: authorization bypasses in foreman-tasks leading to information disclosure2019-07-11
CVE-2019-10198 — Theforeman Foreman-tasks vulnerability | cvebase