Executive brief
A vulnerability in the foreman-mcp-server component of Red Hat Satellite can lead to the accidental recording of sensitive login information in system logs. The software fails to properly hide session identifiers and authentication tokens, such as API keys and passwords, when recording activity for troubleshooting. If these logs are collected or viewed by unauthorized individuals, it could allow them to gain access to the system or sensitive data.
Technical details
The foreman-mcp-server suffers from two logging-related information disclosure issues (CWE-532). First, it fails to suppress INFO-level logs from the underlying MCP Python SDK, which records session identifiers that the server improperly treats as authentication credentials. Second, the LoggingMiddleware component uses an incomplete block-list for sanitizing HTTP headers during DEBUG-level logging; it fails to mask critical headers like 'Authorization', 'Cookie', and 'X-Satellite-Secret'. An attacker with access to container logs or centralized log aggregation platforms (like ELK or Splunk) can retrieve these cleartext credentials to perform session hijacking or unauthorized API access. The vulnerability is present in the foreman-mcp-server-rhel9 package used in Red Hat Satellite 6.
Affected products
- Red Hat Red Hat Satellite 6 satellite/foreman-mcp-server-rhel9
Timeline
- 2026-05-20: disclosed: Initial report in Red Hat Bugzilla
- 2026-06-23: advisory: NVD and Red Hat published advisory details