Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2662

Опубликовано: 22 авг. 2018
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:theforeman:katello:3.4.5:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-862
CWE-269

Связанные уязвимости

CVSS3: 4.3
redhat
почти 9 лет назад

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

CVSS3: 4.3
debian
больше 7 лет назад

A flaw was found in Foreman's katello plugin version 3.4.5. After sett ...

CVSS3: 4.3
github
больше 3 лет назад

katello Improper Privilege Management vulnerability

EPSS

Процентиль: 31%
0.00118
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-862
CWE-269