CVE-2024-6861
Foreman: foreman: oauth secret exposure via unauthenticated access to the graphql api
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.
| CWE | CWE-200 |
| Published | Nov 6, 2024 |
| Last Updated | Nov 20, 2025 |
Stay Ahead of the Next One
Get instant alerts for
Be the first to know when new high vulnerabilities are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Red Hat / Red Hat Satellite 6.12 for RHEL 8
All versions affected Red Hat / Red Hat Satellite 6
All versions affected Red Hat / Red Hat Satellite 6
All versions affected Red Hat / Red Hat Satellite 6
All versions affected References
access.redhat.com: https://access.redhat.com/errata/RHSA-2022:8506 access.redhat.com: https://access.redhat.com/security/cve/CVE-2024-6861 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2317450 docs.theforeman.org: https://docs.theforeman.org/3.3/Release_Notes/index-katello.html#_foreman_2 projects.theforeman.org: https://projects.theforeman.org/issues/34328
Credits
Red Hat would like to thank Sébastien Vecten for reporting this issue.