Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3845

Опубликовано: 11 апр. 2019
Источник: nvd
CVSS3: 8
CVSS3: 8
CVSS2: 5.2
EPSS Низкий

Описание

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:*
Версия до 6.2 (исключая)

EPSS

Процентиль: 39%
0.00175
Низкий

8 High

CVSS3

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8
redhat
почти 7 лет назад

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

CVSS3: 8
github
больше 3 лет назад

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

CVSS3: 8
fstec
почти 7 лет назад

Уязвимость брокера QPID программного средства централизованного управления жизненным циклом программных продуктов Red Hat Satellite, позволяющая нарушителю получить доступ к методам QMF и выполнить произвольные команды в привилегированном режиме

EPSS

Процентиль: 39%
0.00175
Низкий

8 High

CVSS3

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-284
NVD-CWE-Other