PT-2024-37910 · Foreman · Foreman
Sébastien Vecten
·
Published
2024-11-06
·
Updated
2024-11-07
·
CVE-2024-6861
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
foreman (affected versions not specified)
Description
A disclosure of sensitive information flaw was found in foreman via the "GraphQL API". If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys, which could result in a compromise of the entire product's API.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Foreman