Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-8183

Опубликовано: 01 авг. 2019
Источник: nvd
CVSS3: 7.4
CVSS3: 7.4
CVSS2: 6.5
EPSS Низкий

Описание

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:*
Версия от 1.0 (включая) до 1.15.6 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:satellite:6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00153
Низкий

7.4 High

CVSS3

7.4 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.4
redhat
больше 8 лет назад

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

CVSS3: 7.4
github
больше 3 лет назад

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

EPSS

Процентиль: 36%
0.00153
Низкий

7.4 High

CVSS3

7.4 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other