Bug 2535903 (CVE-2026-92893) - CVE-2026-92893 rubygem-foreman_ansible: Ansible inventory API ignores view_hosts permission filters, exposes hidden parameters
Summary: CVE-2026-92893 rubygem-foreman_ansible: Ansible inventory API ignores view_ho...
Keywords:
Status: NEW
Alias: CVE-2026-92893
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 09:10 UTC by OSIDB Bzimport
Modified: 2026-09-17 09:26 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-17 09:10:54 UTC
The Ansible inventory API in foreman_ansible builds its host set via Host.where(condition_key => ids) in the show_inventory private method of AnsibleInventoriesController. The before_action :authorize filter only confirms the caller holds a view_hosts permission covering the controller action; it does not apply any filter attached to that permission. The taxonomy default scope on Host::Base limits results to the caller's organizations and locations, so this does not cross org/location boundaries. However, a user whose view_hosts is narrowed by a filter (e.g., hostgroup, lifecycle environment, or name pattern) can supply arbitrary host IDs within their organizations and receive full Ansible inventory including parameters flagged as hidden (real values, not masked) and Ansible variable values with hidden_value? set.

The correctly scoped pattern Host.authorized(:view_hosts) is used elsewhere in the same plugin (ApiCommon#find_host_ansible_role). The built-in "Ansible Tower Inventory Reader" role includes view_hosts, making the endpoint reachable without custom roles. No non-default configuration is required.

Introduced in foreman_ansible 3.0.1 (commit 13a1529, 2019-06-27, PR #265) when the inventory preview feature was first created. All versions from 3.0.1 through at least 18.0.2 are affected.


Note You need to log in before you can comment on or make changes to this bug.