CVE-2017-2662: Medium severity katello vulnerability
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
Other sources
Brad Buckingham of Red Hat reports:
After settings a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
External reference: http://projects.theforeman.org/issues/18838
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2662?
CVE-2017-2662 has a medium severity rating due to the potential for users to access repositories improperly.
How do I fix CVE-2017-2662?
To fix CVE-2017-2662, upgrade to Foreman Katello version 3.4.5 or apply available patches from Red Hat.
What software is affected by CVE-2017-2662?
CVE-2017-2662 affects Foreman Katello version 3.4.5 and specific versions of the Foreman package.
What does CVE-2017-2662 involve?
CVE-2017-2662 involves a flaw where repository access filters are not respected when using hammer commands.
Who reported CVE-2017-2662?
CVE-2017-2662 was reported by Brad Buckingham of Red Hat.