Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2143

Опубликовано: 24 мар. 2014
Источник: redhat
CVSS2: 4
EPSS Средний

Описание

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6katelloNot affected
Red Hat Subscription Asset ManagerkatelloWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=970849Katello: /app/controllers/users_controller.rb insufficient privilege check

EPSS

Процентиль: 98%
0.6343
Средний

4 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

github
больше 3 лет назад

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

EPSS

Процентиль: 98%
0.6343
Средний

4 Medium

CVSS2