First published: Wed Mar 08 2017(Updated: )
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/foreman | <0:2.3.1.20-1.el7 | 0:2.3.1.20-1.el7 |
Katello | =3.4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2662 has a medium severity rating due to the potential for users to access repositories improperly.
To fix CVE-2017-2662, upgrade to Foreman Katello version 3.4.5 or apply available patches from Red Hat.
CVE-2017-2662 affects Foreman Katello version 3.4.5 and specific versions of the Foreman package.
CVE-2017-2662 involves a flaw where repository access filters are not respected when using hammer commands.
CVE-2017-2662 was reported by Brad Buckingham of Red Hat.