A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
CVSS Details
- CVSS 3.1 Base Score: 8
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- CVSS 3.0 Vector: (CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | centos-upgrade-foreman-clicentos-upgrade-gofercentos-upgrade-katello-agentcentos-upgrade-katello-host-toolscentos-upgrade-katello-host-tools-fact-plugincentos-upgrade-katello-host-tools-tracercentos-upgrade-pulp-puppet-toolscentos-upgrade-pulp-rpm-handlerscentos-upgrade-puppet-agentcentos-upgrade-python-argcompletecentos-upgrade-python-gofercentos-upgrade-python-gofer-protoncentos-upgrade-python-hashlibcentos-upgrade-python-hashlib-debuginfocentos-upgrade-python-isodatecentos-upgrade-python-psutilcentos-upgrade-python-psutil-debuginfocentos-upgrade-python-psutil-debugsourcecentos-upgrade-python-pulp-agent-libcentos-upgrade-python-pulp-commoncentos-upgrade-python-pulp-manifestcentos-upgrade-python-pulp-puppet-commoncentos-upgrade-python-pulp-rpm-commoncentos-upgrade-python-qpid-protoncentos-upgrade-python-uuidcentos-upgrade-python2-beautifulsoup4centos-upgrade-python2-futurecentos-upgrade-python2-tracercentos-upgrade-python3-beautifulsoup4centos-upgrade-python3-futurecentos-upgrade-python3-gofercentos-upgrade-python3-gofer-protoncentos-upgrade-python3-psutilcentos-upgrade-python3-psutil-debuginfocentos-upgrade-python3-qpid-protoncentos-upgrade-python3-qpid-proton-debuginfocentos-upgrade-python3-tracercentos-upgrade-qpid-proton-ccentos-upgrade-qpid-proton-c-debuginfocentos-upgrade-qpid-proton-cpp-debuginfocentos-upgrade-qpid-proton-debuginfocentos-upgrade-qpid-proton-debugsourcecentos-upgrade-rubygem-foreman_scap_clientcentos-upgrade-rubygem-jsoncentos-upgrade-rubygem-json-debuginfocentos-upgrade-satellitecentos-upgrade-satellite-brandingcentos-upgrade-satellite-clicentos-upgrade-tfm-ror52-rubygem-mime-typescentos-upgrade-tfm-ror52-rubygem-mime-types-datacentos-upgrade-tfm-ror52-rubygem-multi_jsoncentos-upgrade-tfm-ror52-runtimecentos-upgrade-tfm-rubygem-apipie-bindingscentos-upgrade-tfm-rubygem-awesome_printcentos-upgrade-tfm-rubygem-clampcentos-upgrade-tfm-rubygem-domain_namecentos-upgrade-tfm-rubygem-fast_gettextcentos-upgrade-tfm-rubygem-hammer_clicentos-upgrade-tfm-rubygem-hammer_cli_csvcentos-upgrade-tfm-rubygem-hammer_cli_foremancentos-upgrade-tfm-rubygem-hammer_cli_foreman_admincentos-upgrade-tfm-rubygem-hammer_cli_foreman_ansiblecentos-upgrade-tfm-rubygem-hammer_cli_foreman_bootdiskcentos-upgrade-tfm-rubygem-hammer_cli_foreman_discoverycentos-upgrade-tfm-rubygem-hammer_cli_foreman_dockercentos-upgrade-tfm-rubygem-hammer_cli_foreman_openscapcentos-upgrade-tfm-rubygem-hammer_cli_foreman_remote_executioncentos-upgrade-tfm-rubygem-hammer_cli_foreman_taskscentos-upgrade-tfm-rubygem-hammer_cli_foreman_templatescentos-upgrade-tfm-rubygem-hammer_cli_foreman_virt_who_configurecentos-upgrade-tfm-rubygem-hammer_cli_katellocentos-upgrade-tfm-rubygem-hashiecentos-upgrade-tfm-rubygem-highlinecentos-upgrade-tfm-rubygem-http-cookiecentos-upgrade-tfm-rubygem-little-pluggercentos-upgrade-tfm-rubygem-localecentos-upgrade-tfm-rubygem-loggingcentos-upgrade-tfm-rubygem-netrccentos-upgrade-tfm-rubygem-oauthcentos-upgrade-tfm-rubygem-powerbarcentos-upgrade-tfm-rubygem-rest-clientcentos-upgrade-tfm-rubygem-unfcentos-upgrade-tfm-rubygem-unf_extcentos-upgrade-tfm-rubygem-unf_ext-debuginfocentos-upgrade-tfm-rubygem-unicodecentos-upgrade-tfm-rubygem-unicode-debuginfocentos-upgrade-tfm-rubygem-unicode-display_widthcentos-upgrade-tfm-runtimecentos-upgrade-tracer-common | Aug 28, 2019 | Apr 11, 2019 |
| Redhat_linux | — | redhat-upgrade-foreman-cliredhat-upgrade-goferredhat-upgrade-katello-agentredhat-upgrade-katello-host-toolsredhat-upgrade-katello-host-tools-fact-pluginredhat-upgrade-katello-host-tools-tracerredhat-upgrade-pulp-puppet-toolsredhat-upgrade-pulp-rpm-handlersredhat-upgrade-puppet-agentredhat-upgrade-python-argcompleteredhat-upgrade-python-goferredhat-upgrade-python-gofer-protonredhat-upgrade-python-hashlibredhat-upgrade-python-hashlib-debuginforedhat-upgrade-python-isodateredhat-upgrade-python-psutilredhat-upgrade-python-psutil-debuginforedhat-upgrade-python-psutil-debugsourceredhat-upgrade-python-pulp-agent-libredhat-upgrade-python-pulp-commonredhat-upgrade-python-pulp-manifestredhat-upgrade-python-pulp-puppet-commonredhat-upgrade-python-pulp-rpm-commonredhat-upgrade-python-qpid-protonredhat-upgrade-python-uuidredhat-upgrade-python2-beautifulsoup4redhat-upgrade-python2-futureredhat-upgrade-python2-tracerredhat-upgrade-python3-beautifulsoup4redhat-upgrade-python3-futureredhat-upgrade-python3-goferredhat-upgrade-python3-gofer-protonredhat-upgrade-python3-psutilredhat-upgrade-python3-psutil-debuginforedhat-upgrade-python3-qpid-protonredhat-upgrade-python3-qpid-proton-debuginforedhat-upgrade-python3-tracerredhat-upgrade-qpid-proton-credhat-upgrade-qpid-proton-c-debuginforedhat-upgrade-qpid-proton-cpp-debuginforedhat-upgrade-qpid-proton-debuginforedhat-upgrade-qpid-proton-debugsourceredhat-upgrade-rubygem-foreman_scap_clientredhat-upgrade-rubygem-jsonredhat-upgrade-rubygem-json-debuginforedhat-upgrade-satelliteredhat-upgrade-satellite-brandingredhat-upgrade-satellite-cliredhat-upgrade-tfm-ror52-rubygem-mime-typesredhat-upgrade-tfm-ror52-rubygem-mime-types-dataredhat-upgrade-tfm-ror52-rubygem-multi_jsonredhat-upgrade-tfm-ror52-runtimeredhat-upgrade-tfm-rubygem-apipie-bindingsredhat-upgrade-tfm-rubygem-awesome_printredhat-upgrade-tfm-rubygem-clampredhat-upgrade-tfm-rubygem-domain_nameredhat-upgrade-tfm-rubygem-fast_gettextredhat-upgrade-tfm-rubygem-hammer_cliredhat-upgrade-tfm-rubygem-hammer_cli_csvredhat-upgrade-tfm-rubygem-hammer_cli_foremanredhat-upgrade-tfm-rubygem-hammer_cli_foreman_adminredhat-upgrade-tfm-rubygem-hammer_cli_foreman_ansibleredhat-upgrade-tfm-rubygem-hammer_cli_foreman_bootdiskredhat-upgrade-tfm-rubygem-hammer_cli_foreman_discoveryredhat-upgrade-tfm-rubygem-hammer_cli_foreman_dockerredhat-upgrade-tfm-rubygem-hammer_cli_foreman_openscapredhat-upgrade-tfm-rubygem-hammer_cli_foreman_remote_executionredhat-upgrade-tfm-rubygem-hammer_cli_foreman_tasksredhat-upgrade-tfm-rubygem-hammer_cli_foreman_templatesredhat-upgrade-tfm-rubygem-hammer_cli_foreman_virt_who_configureredhat-upgrade-tfm-rubygem-hammer_cli_katelloredhat-upgrade-tfm-rubygem-hashieredhat-upgrade-tfm-rubygem-highlineredhat-upgrade-tfm-rubygem-http-cookieredhat-upgrade-tfm-rubygem-little-pluggerredhat-upgrade-tfm-rubygem-localeredhat-upgrade-tfm-rubygem-loggingredhat-upgrade-tfm-rubygem-netrcredhat-upgrade-tfm-rubygem-oauthredhat-upgrade-tfm-rubygem-powerbarredhat-upgrade-tfm-rubygem-rest-clientredhat-upgrade-tfm-rubygem-unfredhat-upgrade-tfm-rubygem-unf_extredhat-upgrade-tfm-rubygem-unf_ext-debuginforedhat-upgrade-tfm-rubygem-unicoderedhat-upgrade-tfm-rubygem-unicode-debuginforedhat-upgrade-tfm-rubygem-unicode-display_widthredhat-upgrade-tfm-runtimeredhat-upgrade-tracer-common | May 15, 2019 | Apr 11, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub