PT-2018-2975 · Red Hat · Foreman+1

Publicado

2018-10-11

·

Atualizado

2019-10-09

·

CVE-2018-14666

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Satellite 6 versions
Description An improper authorization flaw was found in the Smart Class feature of Foreman, allowing an attacker to change the configuration of any host registered in Red Hat Satellite, regardless of the organization the host belongs to. This issue is related to incorrect authorization in the implementation of the Smart Class feature in Red Hat Satellite and Foreman, which could enable a remote attacker to modify configuration files.
Recommendations For Red Hat Satellite 6 versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-02945
CVE-2018-14666

Produtos afetados

Foreman
Red Hat Satellite