Redhat Satellite vulnerabilities
232 known vulnerabilities affecting redhat/satellite.
Total CVEs
232
CISA KEV
4
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL30HIGH59MEDIUM115LOW28
Vulnerabilities
Page 4 of 12
CVE-2020-14334P3HIGHCVSS 8.8v6.02020-07-31
CVE-2020-14334 [HIGH] CWE-522 CVE-2020-14334: A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.
nvd
CVE-2023-1832P3HIGHCVSS 8.1v6.02023-10-04
CVE-2023-1832 [HIGH] CWE-284 CVE-2023-1832: An improper access control flaw was found in Candlepin. An attacker can create data scoped under ano
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
nvd
CVE-2021-44420P3HIGHCVSS 7.3v6.02021-12-08
CVE-2021-44420 [HIGH] CVE-2021-44420: In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with t
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
nvd
CVE-2018-1097P3HIGHCVSS 8.8v6.42018-04-04
CVE-2018-1097 [HIGH] CWE-200 CVE-2018-1097: A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for power
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
nvd
CVE-2017-10067P3HIGHCVSS 7.5v5.82017-08-08
CVE-2017-10067 [HIGH] CVE-2017-10067: Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported version
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than t
nvd
CVE-2017-10115P3HIGHCVSS 7.5v5.82017-08-08
CVE-2017-10115 [HIGH] CVE-2017-10115: Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: J
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE
nvd
CVE-2017-10388P3HIGHCVSS 7.5v5.82017-10-19
CVE-2017-10388 [HIGH] CVE-2017-10388: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java SE, Java SE Embedded. Successful attac
nvd
CVE-2016-9842P3HIGHCVSS 8.8v5.82017-05-23
CVE-2016-9842 [HIGH] CWE-1335 CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
nvd
CVE-2021-3414P3HIGHCVSS 8.1v6.7vSatellite v6.72022-08-26
CVE-2021-3414 [HIGH] CWE-281 CVE-2021-3414: A flaw was found in satellite. When giving granular permission related to the organization, other pe
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2016-9840P3HIGHCVSS 8.8v5.82017-05-23
CVE-2016-9840 [HIGH] CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by lever
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
nvd
CVE-2018-1090P3HIGHCVSS 7.5v6.42018-06-18
CVE-2018-1090 [HIGH] CWE-200 CVE-2018-1090: In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and th
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
nvd
CVE-2020-14380P3HIGHCVSS 7.5v6.7.22021-06-02
CVE-2020-14380 [HIGH] CWE-287 CVE-2020-14380: An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with prop
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.
nvd
CVE-2021-3589P3HIGHCVSS 8.0v6.02022-03-23
CVE-2021-3589 [HIGH] CWE-306 CVE-2021-3589: An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissio
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2019-3845P3HIGHCVSS 8.0fixed in 6.22019-04-11
CVE-2019-3845 [HIGH] CWE-284 CVE-2019-3845: A lack of access control was found in the message queues maintained by Satellite's QPID broker and u
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to S
nvd
CVE-2016-9843P3CRITICALCVSS 9.8v5.82017-05-23
CVE-2016-9843 [CRITICAL] CVE-2016-9843: The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unsp
The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
nvd
CVE-2025-9572P3MEDIUMCVSS 6.5v6.15v6.16+2 more2026-02-27
CVE-2025-9572 [MEDIUM] CWE-863 CVE-2025-9572: n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
nvd
CVE-2021-42550P3MEDIUMCVSS 6.6v6.02021-12-16
CVE-2021-42550 [MEDIUM] CWE-502 CVE-2021-42550: In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit config
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
nvd
CVE-2014-8183P3HIGHCVSS 7.4v6.02019-08-01
CVE-2014-8183 [HIGH] CWE-284 CVE-2014-8183: It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce acc
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
nvd
CVE-2016-0264P3MEDIUMCVSS 5.6v5.6v5.72016-05-24
CVE-2016-0264 [MEDIUM] CWE-119 CVE-2016-0264: Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2013-4480P3HIGHCVSS 7.5≤ 5.62013-11-18
CVE-2013-4480 [HIGH] CWE-668 CVE-2013-4480: Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the firs
Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.
nvd