CVE-2024-4871 - CVE House
Back to Database
Status published Medium CVE-2024-4871

Foreman: host ssh key not being checked in remote execution

Vulnerability Description

A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-4871

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Satellite 6.15 for RHEL 8
Vulnerable Versions:
3.9.1.8, 0:4.3.14-1.el8sat, 0:3.9.1.8-1.el8sat, 1:3.9.3.2-1.el8sat, 0:2.16.9-1.el8pc, 0:3.39.15-1.el8pc, 0:1.8.3-1.el8sat, 0:13.0.6-1.el8sat, 0:12.0.7-1.el8sat, 0:4.11.0.15-1.el8sat, 0:3.0.0-1.el8sat, 0:0.10.6-1.el8sat, 0:6.15.2-1.el8sat

Timeline

Official Publish: May 14th, 2024
Last Modified: February 25th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.