Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47859 | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API. |
Solution
No solution given by the vendor.
Workaround
To mitigate this issue the GraphQL introspection feature must be disabled or the GraphQL API be disabled entirely. Malicious requests can also be filtered using a reverse proxy or directly in the web server configuration.
Tue, 28 Oct 2025 10:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:satellite:6 |
Thu, 09 Oct 2025 21:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Sat, 12 Jul 2025 22:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 07 Nov 2024 02:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Nov 2024 00:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Title | foreman: foreman: OAuth secret exposure via unauthenticated access to the GraphQL API | Foreman: foreman: oauth secret exposure via unauthenticated access to the graphql api |
| First Time appeared |
Redhat satellite Maintenance
Redhat satellite Utils |
|
| CPEs | cpe:/a:redhat:satellite:6 cpe:/a:redhat:satellite_maintenance:6.12::el8 cpe:/a:redhat:satellite_utils:6.12::el8 |
|
| Vendors & Products |
Redhat satellite Maintenance
Redhat satellite Utils |
|
| References |
|
Thu, 10 Oct 2024 11:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule |
|
| CPEs | cpe:/a:redhat:satellite:6.12::el8 cpe:/a:redhat:satellite_capsule:6.12::el8 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule |
Wed, 09 Oct 2024 22:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API. | |
| Title | foreman: foreman: OAuth secret exposure via unauthenticated access to the GraphQL API | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T07:31:26.304Z
Reserved: 2024-07-17T20:36:00.703Z
Link: CVE-2024-6861
Updated: 2024-11-06T16:16:11.767Z
Status : Awaiting Analysis
Published: 2024-11-06T15:15:20.187
Modified: 2024-11-06T18:17:17.287
Link: CVE-2024-6861
OpenCVE Enrichment
No data.
EUVD