← Back

Satellite

satellite

Vendor: Redhat • 232 CVEs

CVEs (232)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Oct 3, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Sep 22, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, poss...Show more
A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, possibly resulting in arbitrary command execution on the underlying operating system.Show less
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Sep 20, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Sep 20, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system.
1Redhat
1Satellite
Jun 17, 2026
Sep 12, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the sy...Show more
A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an attacker with an existing account on the system can steal another user's session, make requests on behalf of the user, and obtain user credentials.Show less
1Redhat
1Satellite
Jun 17, 2026
Dec 16, 2022
N/A· v4
4.5 MEDIUM· v3
N/A· v2
A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific r...Show more
A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.Show less
2Pulpproject
Redhat
4Ansible Automation Platform
Pulp AnsibleSatellite+1 more
Jun 17, 2026
Oct 25, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.
3Ibm
RedhatSuse
8Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+5 more
Nov 21, 2024
Sep 29, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information i...Show more
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file.Show less
1Redhat
1Satellite
Jun 17, 2026
Aug 26, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerab...Show more
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.Show less
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Aug 22, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality...Show more
A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
2Redhat
Theforeman
2Foreman Ansible
Satellite
Jun 17, 2026
Mar 23, 2022
N/A· v4
8.0 HIGH· v3
6.5 MEDIUM· v2
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is...Show more
An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access hosts through job templates. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
2Redhat
Theforeman
2Foreman
Satellite
Jun 17, 2026
Dec 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threa...Show more
A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendmail configuration options to overwrite the defaults and perform command injection. The highest threat from this vulnerability is to confidentiality, integrity and availability of system. Fixed releases are 2.4.1, 2.5.1, 3.0.0.Show less
4Netapp
QosRedhat+1 more
6Cloud Manager
LogbackSatellite+3 more
Jun 17, 2026
Dec 16, 2021
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.
5Canonical
DebianDjangoproject+2 more
5Debian Linux
DjangoFedora+2 more
Jun 17, 2026
Dec 8, 2021
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
1Redhat
1Satellite
Jun 17, 2026
Jun 2, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already ex...Show more
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.Show less
1Redhat
1Satellite
Jun 17, 2026
Jun 2, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite.
1Redhat
1Satellite
Jun 17, 2026
Jun 2, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The high...Show more
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The highest threat from this vulnerability is to system availability.Show less
2Redhat
Theforeman
3Foreman Ansible
SatelliteSatellite Capsule
Jun 17, 2026
May 27, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the abili...Show more
A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a malicious Satellite user to scan through the Job Invocation, with the ability to search for passwords and other sensitive data. This flaw affects tfm-rubygem-foreman_ansible versions before 4.0.3.4.Show less
2Redhat
Theforeman
2Foreman Azurerm
Satellite
Jun 17, 2026
Apr 8, 2021
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The h...Show more
A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Azure Resource Manager's secret key through JSON of the API output. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Redhat
1Satellite
Jun 17, 2026
Feb 23, 2021
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confident...Show more
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less