Bug 1262443 (CVE-2015-5233) - CVE-2015-5233 foreman: reports show/destroy not restricted by host authorization
Summary: CVE-2015-5233 foreman: reports show/destroy not restricted by host authorization
Alias: CVE-2015-5233
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1263741
Blocks: 1247734 1262445
TreeView+ depends on / blocked
Reported: 2015-09-11 17:04 UTC by Kurt Seifried
Modified: 2019-09-29 13:36 UTC (History)
26 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
A flaw was discovered where Satellite failed to properly enforce permissions on the show and delete actions for reports. An authenticated user with show or delete report permissions could use this flaw to view or delete any reports held in Foreman.
Clone Of:
Last Closed: 2015-12-15 10:53:34 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:2622 0 normal SHIPPED_LIVE Moderate: Satellite 6.1.5 bug fix update 2015-12-15 14:17:45 UTC

Description Kurt Seifried 2015-09-11 17:04:18 UTC
Dominic Cleal of the Red Hat Satellite Team reports:

Reports (from tools such as Puppet) are stored in Foreman and associated
to the host they came from. Users can be granted permissions to view
and/or destroy reports, and also separate permissions to view certain
hosts. The UI and API only list reports where the user has permission
to view both reports and the host it was from.

The security issue is that both the show and destroy actions for viewing
and deleting individual reports do not limit access to the hosts that
the user has permission to view. A user with permission to view or
destroy reports can do so for any host if they know the ID, or can
easily view the last report for a given host.

External Reference:

Comment 1 errata-xmlrpc 2015-12-15 09:19:29 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.1

Via RHSA-2015:2622 https://access.redhat.com/errata/RHSA-2015:2622

Note You need to log in before you can comment on or make changes to this bug.