Description
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.
Problem types
Client-Side Enforcement of Server-Side Security
Product status
0:3.9.1.13-1.el8sat (rpm) before *
0:3.12.0.11-1.el8sat (rpm) before *
0:3.12.0.11-1.el9sat (rpm) before *
0:3.14.0.10-1.el9sat (rpm) before *
0:3.16.0.4-1.el9sat (rpm) before *
Timeline
| 2025-09-17: | Reported to Red Hat. |
| 2025-11-01: | Made public. |
Credits
Red Hat would like to thank Michał Bartoszuk (stmcyber.pl) for reporting this issue.
References
access.redhat.com/errata/RHSA-2025:19721 (RHSA-2025:19721)
access.redhat.com/errata/RHSA-2025:19832 (RHSA-2025:19832)
access.redhat.com/errata/RHSA-2025:19855 (RHSA-2025:19855)
access.redhat.com/errata/RHSA-2025:19856 (RHSA-2025:19856)
access.redhat.com/security/cve/CVE-2025-10622
bugzilla.redhat.com/show_bug.cgi?id=2396020 (RHBZ#2396020)