PT-2018-2975 · Red Hat · Foreman+1

Published

2018-10-11

·

Updated

2019-10-09

·

CVE-2018-14666

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Satellite 6 versions
Description An improper authorization flaw was found in the Smart Class feature of Foreman, allowing an attacker to change the configuration of any host registered in Red Hat Satellite, regardless of the organization the host belongs to. This issue is related to incorrect authorization in the implementation of the Smart Class feature in Red Hat Satellite and Foreman, which could enable a remote attacker to modify configuration files.
Recommendations For Red Hat Satellite 6 versions, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02945
CVE-2018-14666

Affected Products

Foreman
Red Hat Satellite