CVE-2018-14666
Last modified
CVE-2018-14666 is a vulnerability of currently unknown severity. An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. EPSS estimates a 1.05% chance of exploitation in the next 30 days.
Description
An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Satellite | >= 6.0, <= 6.4 |
References
- http://www.securityfocus.com/bid/106490Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/106490Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14666?
How severe is CVE-2018-14666?
How do I fix CVE-2018-14666?
Are you affected by CVE-2018-14666?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
