CVE-2017-7470: Critical severity redhat Spacewalk vulnerability
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
Other sources
It was found that spacewalk-channel can be used by non-admin or disabled users for performing administrative tasks due to incorrect authorization check in backend/server/rhnChannel.py.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7470?
CVE-2017-7470 has been rated as having a moderate severity due to improper authorization checks.
How do I fix CVE-2017-7470?
To fix CVE-2017-7470, update to the latest versions of Red Hat Spacewalk or Red Hat Satellite that have patches applied.
What are the potential risks of CVE-2017-7470?
The risks associated with CVE-2017-7470 include non-admin or disabled users being able to perform unauthorized administrative tasks.
Which software is affected by CVE-2017-7470?
CVE-2017-7470 affects Red Hat Spacewalk and Red Hat Satellite versions 5.6 and 5.7.
Can CVE-2017-7470 lead to a security breach?
Yes, CVE-2017-7470 can lead to a security breach if unauthorized users exploit the vulnerability.