A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade tfm-rubygem-hammer_cli_foremanUpgrade python-psutil-debugsourceUpgrade tfm-rubygem-powerbarUpgrade katello-host-toolsUpgrade python2-futureUpgrade rubygem-foreman_scap_clientUpgrade python-psutilUpgrade tfm-rubygem-domain_nameUpgrade python-qpid-protonUpgrade katello-host-tools-fact-pluginUpgrade qpid-proton-debuginfoUpgrade katello-agentUpgrade qpid-proton-cpp-debuginfoUpgrade tfm-rubygem-hammer_cli_katelloUpgrade tfm-rubygem-apipie-bindingsUpgrade tfm-rubygem-hammer_cli_foreman_ansibleUpgrade satellite-cliUpgrade tfm-rubygem-unfUpgrade tfm-ror52-runtimeUpgrade python-psutil-debuginfoUpgrade python-gofer-protonUpgrade katello-host-tools-tracerUpgrade tfm-runtimeUpgrade satelliteUpgrade tfm-rubygem-awesome_printUpgrade tfm-rubygem-unicode-display_widthUpgrade tfm-rubygem-hammer_cli_foreman_openscapUpgrade qpid-proton-c-debuginfoUpgrade python3-psutil-debuginfoUpgrade tfm-rubygem-hammer_cli_csvUpgrade tfm-rubygem-little-pluggerUpgrade tfm-rubygem-oauthUpgrade python2-tracerUpgrade tfm-rubygem-loggingUpgrade tfm-rubygem-unf_extUpgrade rubygem-json-debuginfoUpgrade python3-qpid-protonUpgrade python-isodateUpgrade tfm-rubygem-hashieUpgrade tfm-rubygem-unicode-debuginfoUpgrade tfm-rubygem-hammer_cli_foreman_bootdiskUpgrade tfm-rubygem-http-cookieUpgrade tfm-rubygem-hammer_cli_foreman_dockerUpgrade pulp-puppet-toolsUpgrade python-hashlib-debuginfoUpgrade qpid-proton-cUpgrade python3-gofer-protonUpgrade tfm-rubygem-hammer_cliUpgrade python-argcompleteUpgrade python3-psutilUpgrade tfm-ror52-rubygem-multi_jsonUpgrade python-pulp-manifestUpgrade tfm-rubygem-clampUpgrade tfm-rubygem-hammer_cli_foreman_tasksUpgrade python3-qpid-proton-debuginfoUpgrade tfm-rubygem-hammer_cli_foreman_adminUpgrade python-goferUpgrade tfm-rubygem-localeUpgrade goferUpgrade python3-tracerUpgrade python-pulp-agent-libUpgrade tfm-rubygem-hammer_cli_foreman_templatesUpgrade tfm-ror52-rubygem-mime-types-dataUpgrade qpid-proton-debugsourceUpgrade tfm-rubygem-fast_gettextUpgrade python-pulp-commonUpgrade python3-goferUpgrade tfm-rubygem-unf_ext-debuginfoUpgrade python3-beautifulsoup4Upgrade python-pulp-rpm-commonUpgrade tfm-ror52-rubygem-mime-typesUpgrade python-pulp-puppet-commonUpgrade tfm-rubygem-hammer_cli_foreman_remote_executionUpgrade python-uuidUpgrade tfm-rubygem-hammer_cli_foreman_discoveryUpgrade tfm-rubygem-netrcUpgrade pulp-rpm-handlersUpgrade tracer-commonUpgrade tfm-rubygem-rest-clientUpgrade satellite-brandingUpgrade foreman-cliUpgrade rubygem-jsonUpgrade python-hashlibUpgrade tfm-rubygem-hammer_cli_foreman_virt_who_configureUpgrade python2-beautifulsoup4Upgrade tfm-rubygem-highlineUpgrade puppet-agentUpgrade tfm-rubygem-unicodeUpgrade python3-future | Aug 28, 2019 | Apr 11, 2019 |
| Redhat_linux | — | Upgrade tfm-rubygem-domain_nameUpgrade python-pulp-puppet-commonUpgrade python-pulp-commonUpgrade python-psutil-debuginfoUpgrade tfm-rubygem-hammer_cli_katelloUpgrade foreman-cliUpgrade tfm-rubygem-hammer_cli_csvUpgrade python-isodateUpgrade tfm-rubygem-unicode-debuginfoUpgrade python3-goferUpgrade python-psutilUpgrade tfm-rubygem-unicode-display_widthUpgrade pulp-rpm-handlersUpgrade tfm-rubygem-hammer_cli_foremanUpgrade python3-gofer-protonUpgrade python-hashlibUpgrade python-psutil-debugsourceUpgrade qpid-proton-debugsourceUpgrade tfm-rubygem-fast_gettextUpgrade tfm-ror52-rubygem-mime-typesUpgrade python-uuidUpgrade katello-host-tools-fact-pluginUpgrade python-qpid-protonUpgrade python3-qpid-protonUpgrade python2-futureUpgrade python2-beautifulsoup4Upgrade qpid-proton-debuginfoUpgrade rubygem-json-debuginfoUpgrade tfm-rubygem-little-pluggerUpgrade python-pulp-manifestUpgrade tfm-rubygem-apipie-bindingsUpgrade tfm-rubygem-clampUpgrade satellite-brandingUpgrade tfm-rubygem-unfUpgrade tfm-rubygem-hammer_cli_foreman_discoveryUpgrade tfm-rubygem-awesome_printUpgrade python-pulp-agent-libUpgrade tfm-ror52-runtimeUpgrade python-hashlib-debuginfoUpgrade python-gofer-protonUpgrade tfm-rubygem-loggingUpgrade tfm-ror52-rubygem-mime-types-dataUpgrade tfm-ror52-rubygem-multi_jsonUpgrade rubygem-jsonUpgrade tfm-rubygem-netrcUpgrade tfm-rubygem-hammer_cli_foreman_tasksUpgrade tfm-rubygem-hammer_cliUpgrade tfm-rubygem-localeUpgrade tfm-rubygem-highlineUpgrade pulp-puppet-toolsUpgrade qpid-proton-c-debuginfoUpgrade python3-tracerUpgrade tfm-rubygem-rest-clientUpgrade tfm-runtimeUpgrade tfm-rubygem-hammer_cli_foreman_bootdiskUpgrade tfm-rubygem-hammer_cli_foreman_virt_who_configureUpgrade tracer-commonUpgrade tfm-rubygem-hammer_cli_foreman_ansibleUpgrade katello-agentUpgrade python2-tracerUpgrade python3-psutil-debuginfoUpgrade tfm-rubygem-oauthUpgrade tfm-rubygem-hammer_cli_foreman_templatesUpgrade katello-host-tools-tracerUpgrade tfm-rubygem-hashieUpgrade python3-qpid-proton-debuginfoUpgrade tfm-rubygem-unf_extUpgrade satelliteUpgrade tfm-rubygem-unicodeUpgrade satellite-cliUpgrade tfm-rubygem-hammer_cli_foreman_dockerUpgrade puppet-agentUpgrade python-argcompleteUpgrade qpid-proton-cUpgrade katello-host-toolsUpgrade python3-futureUpgrade tfm-rubygem-http-cookieUpgrade rubygem-foreman_scap_clientUpgrade python-goferUpgrade tfm-rubygem-hammer_cli_foreman_adminUpgrade python3-beautifulsoup4Upgrade python-pulp-rpm-commonUpgrade tfm-rubygem-hammer_cli_foreman_openscapUpgrade python3-psutilUpgrade tfm-rubygem-powerbarUpgrade goferUpgrade tfm-rubygem-hammer_cli_foreman_remote_executionUpgrade qpid-proton-cpp-debuginfoUpgrade tfm-rubygem-unf_ext-debuginfo | May 15, 2019 | Apr 11, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub