CVE-2025-10622 Details
Description
A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.
A command injection vulnerability has been identified in the Foreman component of Red Hat Satellite. This issue allows authenticated users with edit_settings permissions to execute arbitrary commands on the underlying operating system. The vulnerability arises from inadequate server-side validation of command whitelisting, as the existing whitelist for CoreOS Transpiler Command and Fedora CoreOS Transpiler Command is only enforced on the client-side.
Users are advised to upgrade to Red Hat Satellite 6.18 for RHEL 9, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 5, 2025CISA-ADP
Assessed Nov 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat Satellite | 6.16.5.2 |
CPE
Remediation
| |
| Red Hat Satellite Capsule | All versions |
CPE
Remediation
| |
| Red Hat Enterprise Linux | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 6, 2026 | CVE Modified | [email protected] |
| Dec 23, 2025 | CVE Modified | [email protected] |
| Nov 6, 2025 | CVE Modified | [email protected] |
| Nov 5, 2025 | New CVE Received | [email protected] |
Volerion