Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhwm-66gm-6j9v

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

EPSS

Процентиль: 98%
0.6343
Средний

Дефекты

CWE-20

Связанные уязвимости

redhat
почти 12 лет назад

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

nvd
почти 12 лет назад

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

EPSS

Процентиль: 98%
0.6343
Средний

Дефекты

CWE-20