CVE-2019-3845: High severity redhat Satellite vulnerability
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
Other sources
A vulnerability was found in qpid-dispatch-router. Any logged user can access QMF methods on Satellite's qpid broker which allows him to (un)install any available package on any system (managed by the Satellite) that runs katello agent / goferd.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3845?
CVE-2019-3845 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2019-3845?
To fix CVE-2019-3845, update your Red Hat Satellite to version 6.2 or later.
What software is affected by CVE-2019-3845?
CVE-2019-3845 affects Red Hat Satellite versions prior to 6.2 and Satellite Capsule 6.1.
Can CVE-2019-3845 be exploited by authenticated users?
Yes, a malicious authenticated user can exploit CVE-2019-3845 to access unauthorized message queues.
Is there a workaround for CVE-2019-3845?
There are no known workarounds for CVE-2019-3845; the recommended solution is to upgrade the software.