CVE-2013-4201: Medium severity katello vulnerability
Hayk Hovsepyan hhovsepy reports:
When user without remove system permissions calls CLI command "system removedeletion", it finishes successfully without any warning.
Other sources
Katello allows remote authenticated users to call the "system removedeletion" CLI command via vectors related to "remove system" permissions.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4201?
The severity of CVE-2013-4201 is classified as medium, as it can be exploited by remote authenticated users.
How do I fix CVE-2013-4201?
To fix CVE-2013-4201, ensure that only authorized users have permission to execute the 'system remove_deletion' CLI command.
Who is affected by CVE-2013-4201?
CVE-2013-4201 affects deployments of Katello, specifically users with remote authenticated access.
What are the potential impacts of exploiting CVE-2013-4201?
Exploiting CVE-2013-4201 could allow unauthorized users to remove system deletions without proper permissions.
Is there a workaround for CVE-2013-4201?
A potential workaround for CVE-2013-4201 is to restrict access to the CLI commands based on user roles and permissions.