Bug 2535942 (CVE-2026-92904) - CVE-2026-92904 rubygem-foreman_remote_execution: Job output readable without object-level view_job_invocations check
Summary: CVE-2026-92904 rubygem-foreman_remote_execution: Job output readable without ...
Keywords:
Status: NEW
Alias: CVE-2026-92904
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-17 11:18 UTC by TEJ RATHI
Modified: 2026-09-17 11:33 UTC (History)
13 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description TEJ RATHI 2026-09-17 11:18:51 UTC
The show_template_invocation_by_host action in TemplateInvocationsController resolves the job invocation via JobInvocation.find(params[:id]) and the host via Host.find(params[:host_id]) without performing an object-level authorization check against the caller's view_job_invocations permission filter. The controller-level before_action :authorize checks only that the caller holds a view_job_invocations permission covering the controller action; it does not evaluate the permission's search filter against the specific record. The sibling show action in the same controller explicitly performs User.current.can?(:view_job_invocations, @template_invocation.job_invocation), which is the object-level form.

JobInvocation includes Authorizable but not Taxonomix and has no taxonomy default scope, so the job invocation ID is unconstrained. Host::Base carries default_scope -> { where(taxonomy_conditions) }, which limits host lookup to the caller's organizations. The attacker must supply a host_id within their organizations that was targeted by the job invocation.

The action returns live output (stdout/stderr), the rendered script preview, template input values (hidden values are masked via input_safe_value), task details, and host/proxy information.

The V2 API controller has a related gap: the output and raw_output actions in Api::V2::JobInvocationsController resolve the JobInvocation via find_optional_nested_object (bare find) rather than find_resource (which applies authorized(:view_job_invocations)). The host IS properly scoped via authorized(:view_hosts), so the V2 gap is bounded by host authorization.

Introduced in foreman_remote_execution v15.0.0 by commit 45bd8b894424c9316516001fa0c44a0cedd70a2b (MariaAga, 2025-01-24, Fixes #38123, "add template invocation info to new job details"). The sibling show action has had the object-level User.current.can? check since 2016 (commit d194bf0, Fixes #13287). The new action added in 2025 did not replicate the check. All versions from v15.0.0 through v18.0.0 (current HEAD) are affected.


Note You need to log in before you can comment on or make changes to this bug.