Bug 1638156 (CVE-2018-14666) - CVE-2018-14666 Satellite: Smart class parameters allow users to access other organizations [NEEDINFO]
Summary: CVE-2018-14666 Satellite: Smart class parameters allow users to access other ...
Status: CLOSED WONTFIX
Alias: CVE-2018-14666
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20190108:1802,...
Keywords: Security
Depends On: 1638555 1638556
Blocks: 1636281
TreeView+ depends on / blocked
 
Reported: 2018-10-11 00:24 UTC by Richard Maciel Costa
Modified: 2019-06-08 23:39 UTC (History)
15 users (show)

(edit)
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Satellite, independent of the organization the host belongs to. This flaw affects all Satellite 6 versions.
Clone Of:
(edit)
Last Closed: 2019-01-08 18:02:35 UTC
orabin: needinfo? (mhulan)


Attachments (Terms of Use)

Description Richard Maciel Costa 2018-10-11 00:24:48 UTC
Smart parameters of classes changed by an user bound to a given organization, reflect on smart parameters of the same-named class in all other organizations. Since classes are used to setup hosts parameters, this could lead to an user of an organization changing configurations of a host located in a different organization.

Comment 4 Richard Maciel Costa 2018-10-15 19:03:47 UTC
Acknowledgments:

Name: Pat Riehecky (Fermilab)


Note You need to log in before you can comment on or make changes to this bug.