Access Control Flaw in Foreman's Katello Plugin by Red Hat
CVE-2017-2662
4.3MEDIUM
What is CVE-2017-2662?
An access control flaw exists in Foreman's Katello Plugin version 3.4.5 that compromises repository security. When a new role is established to restrict access based on a specific product name filter, this restriction is not honored in operations performed via the hammer command-line interface using the repository ID. Consequently, unauthorized users may execute actions on repositories they should not have access to, leading to potential data exposure and integrity risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
foreman katello plugin 3.4.5
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
