CVE-2024-7923 - Foreman Apache Mod_Proxy Authentication Bypass Vulnerability

1 month ago 17
ARTICLE AD BOX
CVE ID : CVE-2024-7923
Published : Sept. 4, 2024, 2:15 p.m. | 24 minutes ago
Description : An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 4.0+ and could potentially enable unauthorized users to gain administrative access.
Severity: 4.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article