An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Satellite, independent of the organization the host belongs to. This flaw affects all Satellite 6 versions.
Smart parameters of classes changed by an user bound to a given organization, reflect on smart parameters of the same-named class in all other organizations. Since classes are used to setup hosts parameters, this could lead to an user of an organization changing configurations of a host located in a different organization.
Name: Pat Riehecky (Fermilab)