Authorization Flaw in Foreman's GraphQL API Affects Red Hat
CVE-2025-9572

5MEDIUM

What is CVE-2025-9572?

An authorization flaw in Foreman's GraphQL API presents a significant concern for users, enabling low-privileged users to gain access to sensitive metadata beyond their assigned permissions. Unlike the REST API, which enforces proper access controls, the GraphQL endpoint lacks sufficient filtering measures. This oversight allows unauthorized information retrieval, potentially leading to data leakage and security compliance issues.

Affected Version(s)

Foreman 1.22.0 < 3.16.2

Red Hat Satellite 6.15 for RHEL 8 0:3.9.1.14-1.el8sat

Red Hat Satellite 6.15 for RHEL 8 0:6.15.5.7-1.el8sat

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Ohad Levy (Redhat) for reporting this issue.
.