PT-2021-9171 · Red Hat+1 · Tfm-Rubygem-Foreman Ansible+1

Cedric Buissart

·

Published

2021-05-27

·

Updated

2025-08-06

·

CVE-2020-10716

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Satellite tfm-rubygem-foreman ansible versions prior to 4.0.3.4
Description A flaw in Red Hat Satellite's Job Invocation allows a malicious user to scan through the invocation, potentially searching for passwords and other sensitive data due to improper restriction of the "User Input" entry.
Recommendations For tfm-rubygem-foreman ansible versions prior to 4.0.3.4, update to version 4.0.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Job Invocation feature to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-11761
CVE-2020-10716
RHSA-2020:1454

Affected Products

Red Os
Tfm-Rubygem-Foreman Ansible