CVE-2024-7012 - Foreman Apache ModProxy Header Authentication Bypass

1 month ago 16
ARTICLE AD BOX
CVE ID : CVE-2024-7012
Published : Sept. 4, 2024, 2:15 p.m. | 24 minutes ago
Description : An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) and could potentially enable unauthorized users to gain administrative access.
Severity: 9.8 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article