First published: Sat Aug 12 2017(Updated: )
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
The Foreman | >=1.0<1.15.6 | |
Red Hat Satellite | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8183 is classified as a medium severity vulnerability due to improper access control enforcement.
To remediate CVE-2014-8183, upgrade foreman to version 1.15.6 or later.
CVE-2014-8183 affects foreman versions 1.x.x before 1.15.6.
CVE-2014-8183 affects Red Hat Satellite version 6.0.
The consequences of CVE-2014-8183 include unauthorized access to resources in other organizations if an attacker exploits the vulnerability.