PT-2020-3466 · Red Hat · Red Hat Satellite
Yadnyawalk Tale
·
Published
2020-07-17
·
Updated
2023-02-12
·
CVE-2020-14334
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Satellite 6
Description
The issue is related to inadequate access control in Red Hat Satellite, allowing a privileged attacker to read cache files. These cache credentials could help the attacker gain complete control of the Satellite instance.
Recommendations
For Red Hat Satellite 6, consider restricting access to cache files as a temporary workaround until a patch is available. Additionally, review and limit privileged access to the Satellite instance to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Satellite