6.8 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): NONE
Foreman: host ssh key not being checked in remote execution
A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being checked. When the key changes, the Satellite still connects it because it uses "-o StrictHostKeyChecking=no". This flaw can lead to a man-in-the-middle attack (MITM), denial of service, leaking of secrets the remote execution job contains, or other issues that may arise from the attacker's ability to forge an SSH key. This issue does not directly allow unauthorized remote execution on the Satellite, although it can leak secrets that may lead to it.
References
Affected products
- ==3.9.1.8
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
- *
Matching in nixpkgs
pkgs.foreman
Process manager for applications with multiple components
pkgs.satellite
Program for showing navigation satellite data
pkgs.wyoming-satellite
Remote voice satellite using Wyoming protocol
pkgs.xwayland-satellite
Xwayland outside your Wayland compositor
pkgs.homeassistant-satellite
Streaming audio satellite for Home Assistant
pkgs.vimPlugins.satellite-nvim
None
-
nixos-unstable 2024-11-20
- nixpkgs-unstable 2024-11-20
- nixos-unstable-small 2024-12-05
pkgs.emacsPackages.foreman-mode
None
-
nixos-unstable 20170725.1422
- nixpkgs-unstable 20170725.1422
- nixos-unstable-small 20170725.1422
pkgs.home-assistant-component-tests.assist_satellite
Open source home automation that puts local control and privacy first
Package maintainers
-
@zimbatm zimbatm <zimbatm@zimbatm.com>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@Luflosi Luflosi <luflosi@luflosi.de>
-
@sodiboo sodiboo
-
@if-loop69420 Jeremy Sztavinovszki <j.sztavi@pm.me>
-
@getchoo Seth Flynn <getchoo@tuta.io>