PT-2018-7165 · Foreman · Foreman+1

CVE-2017-2662

·

Publicado

2018-08-22

·

Atualizado

2023-02-12

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Foreman's katello plugin version 3.4.5
Description: A flaw was found in Foreman's katello plugin. The issue occurs when a new role is set to allow restricted access on a repository with a filter, specifically a filter set on the Product Name. In this scenario, the filter is not respected when actions are performed via hammer using the repository id.
Recommendations: For Foreman's katello plugin version 3.4.5, consider restricting access to the repository id in hammer until a fix is available. As a temporary workaround, avoid using the repository id in hammer for actions related to repositories with filters set on the Product Name.

Correção

Missing Authorization

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2662
GHSA-CPV6-PFQ6-J2V7
RHSA-2021:1313

Produtos afetados

Foreman
Katello Plugin