Home

Description

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

PUBLISHED Reserved 2025-08-28 | Published 2026-02-27 | Updated 2026-02-27 | Assigner redhat




MEDIUM: 5.0CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Problem types

Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unaffected

1.22.0 (semver) before 3.16.2
affected

Default status
affected

0:3.9.1.14-1.el8sat (rpm) before *
unaffected

Default status
affected

0:6.15.5.7-1.el8sat (rpm) before *
unaffected

Default status
affected

0:3.12.0.12-1.el8sat (rpm) before *
unaffected

Default status
affected

0:6.16.5.6-1.el8sat (rpm) before *
unaffected

Default status
affected

0:3.12.0.12-1.el9sat (rpm) before *
unaffected

Default status
affected

0:6.16.5.6-1.el9sat (rpm) before *
unaffected

Default status
affected

0:3.14.0.11-1.el9sat (rpm) before *
unaffected

Default status
affected

0:3.16.0.7-1.el9sat (rpm) before *
unaffected

Default status
affected

0:4.18.0.4-1.el9sat (rpm) before *
unaffected

Default status
affected

0:6.18.1-1.el9sat (rpm) before *
unaffected

Timeline

2025-08-29:Reported to Red Hat.
2025-08-29:Made public.

Credits

Red Hat would like to thank Ohad Levy (Redhat) for reporting this issue.

References

access.redhat.com/errata/RHSA-2025:21886 (RHSA-2025:21886) vendor-advisory

access.redhat.com/errata/RHSA-2025:21893 (RHSA-2025:21893) vendor-advisory

access.redhat.com/errata/RHSA-2025:21894 (RHSA-2025:21894) vendor-advisory

access.redhat.com/errata/RHSA-2025:21897 (RHSA-2025:21897) vendor-advisory

access.redhat.com/security/cve/CVE-2025-9572 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2391715 (RHBZ#2391715) issue-tracking

theforeman.org/security.html

cve.org (CVE-2025-9572)

nvd.nist.gov (CVE-2025-9572)

Download JSON