Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cpv6-pfq6-j2v7

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

katello Improper Privilege Management vulnerability

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

Пакеты

Наименование

katello

rubygems
Затронутые версииВерсия исправления

< 3.17.0.rc1

3.17.0.rc1

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 4.3
redhat
почти 9 лет назад

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

CVSS3: 4.3
nvd
больше 7 лет назад

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

CVSS3: 4.3
debian
больше 7 лет назад

A flaw was found in Foreman's katello plugin version 3.4.5. After sett ...

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-269