CVE-2025-9572
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
Affected (10)
Products: Theforeman: Foreman · Redhat: Enterprise Linux, Satellite, Satellite Capsule
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 1.22.0 to 3.16.2 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.0 | |
| Version 6.15 | |
| Version 6.15 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-863
Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
References (7)
Timeline
No history available yet.