<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Red Hat Satellite (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/redhat-satellite.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/redhat-satellite-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Red Hat Satellite (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-0980 – A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-0980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-0980</guid>
    <pubDate>Fri, 27 Feb 2026 08:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-0980</strong></p>
  <p>A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-0980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10622 – A flaw was found in Red Hat Satellite (Foreman component). This vulnerability al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10622</guid>
    <pubDate>Wed, 05 Nov 2025 08:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10622</strong></p>
  <p>A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14380 – An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potentia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14380</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14380</guid>
    <pubDate>Wed, 02 Jun 2021 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14380</strong></p>
  <p>An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14380">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14334 – A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14334</guid>
    <pubDate>Fri, 31 Jul 2020 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14334</strong></p>
  <p>A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain complete control of the Satellite instance.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-3891 – It was discovered that a world-readable log file belonging to Candlepin componen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-3891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-3891</guid>
    <pubDate>Mon, 15 Apr 2019 12:31:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-3891</strong></p>
  <p>It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-3891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5164 – The Qpid server on Red Hat Satellite 6 does not properly restrict message types,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5164</guid>
    <pubDate>Wed, 18 Oct 2017 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5164</strong></p>
  <p>The Qpid server on Red Hat Satellite 6 does not properly restrict message types, which allows remote authenticated users with administrative access on a managed content host to execute arbitrary code via a crafted message, related to a pickle processing problem in pulp.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4480 – Red Hat Satellite 5.6 and earlier does not disable the web interface that is use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4480</guid>
    <pubDate>Mon, 18 Nov 2013 02:55:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4480</strong></p>
  <p>Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4480">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
