Dismissed
Permalink
CVE-2025-9572
5.0 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @anthonyroussel Activity log
- Created suggestion
-
@anthonyroussel
ignored
6 packages
- wyoming-satellite
- xwayland-satellite
- home-assistant-component-tests.assist_satellite
- tests.home-assistant-component-tests.assist_satellite
- foreman
- satellite
- @anthonyroussel dismissed
Foreman: satellite: graphql api permission bypass leads to information disclosure
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
References
Affected products
foreman
- *
- <3.16.2
satellite
- *
rubygem-katello
- *
Ignored packages (6)
pkgs.foreman
Process manager for applications with multiple components
pkgs.satellite
Program for showing navigation satellite data
pkgs.wyoming-satellite
Remote voice satellite using Wyoming protocol
pkgs.xwayland-satellite
Xwayland outside your Wayland compositor
pkgs.tests.home-assistant-component-tests.assist_satellite
Open source home automation that puts local control and privacy first