Fedora Account System
Red Hat Associate
Red Hat Customer
Description The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. -------------------------------------------------------------------------------- /usr/share/foreman/app/services/foreman/unattended_installation/host_verifier.rb def valid_host_token? return true unless @needs_token return true unless for_host_template VULNERABILITY: This only checks if the token in the database is currently expired. It does NOT verify if the requester actually provided a valid token in the URL. return true unless @host&.token_expired? errors << { ... } false end -------------------------------------------------------------------------------- Impact By utilizing the enumeration technique detailed in F-26 Infrastructure Mapping via Observable Response Discrepancy, an unauthenticated remote attacker can actively poll the endpoint for a host entering a build state and extract its complete provisioning template. These templates contain highly sensitive data, including the root user's SHA-512 password hash, internal IP topography, and active API build tokens.
This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505
This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506