Foreman: host ssh key not being checked in remote execution
Published May 14, 2024
6.8
MEDIUMCVSS 3.1
EPSS 0.61%
Description
A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.
Affected products
No data.
No data.
No data.
Red Hat Satellite 6.15 for RHEL 8
candlepin-0:4.3.14-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
foreman-0:3.9.1.8-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
foreman-installer-1:3.9.3.2-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
python-pulp-container-0:2.16.9-1.el8pc
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
python-pulpcore-0:3.39.15-1.el8pc
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
rubygem-dynflow-0:1.8.3-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
rubygem-foreman_ansible-0:13.0.6-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
rubygem-foreman_remote_execution-0:12.0.7-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
rubygem-katello-0:4.11.0.15-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
rubygem-smart_proxy_container_gateway-0:3.0.0-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
rubygem-smart_proxy_remote_execution_ssh-0:0.10.6-1.el8sat
Fixed · RHBA-2024:4589
Red Hat Satellite 6.15 for RHEL 8
satellite-0:6.15.2-1.el8sat
Fixed · RHBA-2024:4589
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.15 for RHEL 8 | candlepin-0:4.3.14-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | foreman-0:3.9.1.8-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | foreman-installer-1:3.9.3.2-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | python-pulp-container-0:2.16.9-1.el8pc | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | python-pulpcore-0:3.39.15-1.el8pc | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | rubygem-dynflow-0:1.8.3-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | rubygem-foreman_ansible-0:13.0.6-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | rubygem-foreman_remote_execution-0:12.0.7-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | rubygem-katello-0:4.11.0.15-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | rubygem-smart_proxy_container_gateway-0:3.0.0-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | rubygem-smart_proxy_remote_execution_ssh-0:0.10.6-1.el8sat | Fixed | RHBA-2024:4589 |
| Red Hat Satellite 6.15 for RHEL 8 | satellite-0:6.15.2-1.el8sat | Fixed | RHBA-2024:4589 |
No package ranges for this CVE.
Remediation
Vendor solution
Currently there is no mitigation available for this vulnerability. Please perform the necessary updates as they become available.
Red Hat statement
Red Hat rates this as a Moderate impact. Even though an attacker may access, they may need a functional SSH key with enough access to jeopardize the environment.
Red Hat mitigation
Currently there is no mitigation available for this vulnerability. Please perform the necessary updates as they become available.
References (5)
- https://access.redhat.com/errata/RHBA-2024:4589 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-4871 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2278627 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-4871
- https://www.cve.org/CVERecord?id=CVE-2024-4871
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHBA-2024:4589 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-4871 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2278627 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-4871 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-4871 |
Change history (0)
No recorded changes yet.