CVE-2013-2143
17.04.2014, 14:55
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | network_satellite | - |
theforeman | katello | 𝑥 ≤ 1.5.0-14 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References