CVE-2013-2143: Input Validation
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the updateroles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2143?
CVE-2013-2143 is classified as a medium severity vulnerability due to the potential for unauthorized privilege escalation.
How do I fix CVE-2013-2143?
To mitigate CVE-2013-2143, upgrade to Katello versions later than 1.5.0-14 and ensure proper authorization checks are implemented.
Who is affected by CVE-2013-2143?
CVE-2013-2143 affects users of Katello versions 1.5.0-14 and earlier, as well as users of Red Hat Satellite.
What is the impact of CVE-2013-2143?
The impact of CVE-2013-2143 allows remote authenticated users to gain unauthorized privileges by altering user accounts to administrators.
Is CVE-2013-2143 a code injection vulnerability?
No, CVE-2013-2143 is not a code injection vulnerability; it is an authorization issue related to user role management.