RubySec

Providing security resources for the Ruby community

CVE-2017-2662 (katello): katello Improper Privilege Management vulnerability

ADVISORIES

GEM

katello

SEVERITY

CVSS v3.x: 4.3 (Medium)

PATCHED VERSIONS

  • >= 3.17.0.rc1

DESCRIPTION

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

RELATED