CVE-2024-6861
Discription
A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API. Mitigation To mitigate this issue the GraphQL introspection feature must be disabled or the GraphQL API be disabled entirely. Malicious requests can also be filtered using a reverse proxy or directly in the web server…Read More
References
Back to Main