CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
References
Link Resource
http://www.securityfocus.com/bid/106490 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-01-22 15:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-14666

Mitre link : CVE-2018-14666

CVE.ORG link : CVE-2018-14666


JSON object : View

Products Affected

redhat

  • satellite
CWE
CWE-863

Incorrect Authorization

CWE-285

Improper Authorization