First published: Thu Apr 06 2017(Updated: )
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Spacewalk | ||
Red Hat Satellite | =5.6 | |
Red Hat Satellite | =5.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7470 has been rated as having a moderate severity due to improper authorization checks.
To fix CVE-2017-7470, update to the latest versions of Red Hat Spacewalk or Red Hat Satellite that have patches applied.
The risks associated with CVE-2017-7470 include non-admin or disabled users being able to perform unauthorized administrative tasks.
CVE-2017-7470 affects Red Hat Spacewalk and Red Hat Satellite versions 5.6 and 5.7.
Yes, CVE-2017-7470 can lead to a security breach if unauthorized users exploit the vulnerability.