CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/106490 - Third Party Advisory () http://www.securityfocus.com/bid/106490 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666 - Issue Tracking, Vendor Advisory
CVSS v2 : 6.5
v3 : 7.2
v2 : 6.5
v3 : 6.8

Information

Published : 2019-01-22 15:29

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14666

Mitre link : CVE-2018-14666

CVE.ORG link : CVE-2018-14666


JSON object : View

Products Affected

redhat

  • satellite
CWE
CWE-285

Improper Authorization

CWE-863

Incorrect Authorization