REDHAT-BUG-1112813: Medium severity luci vulnerability
Various components in the /luci/homebase and /luci/cluster menu, which should be restricted to administrative users only, are exposed to any logged-in (non-administrative, but authenticated) user if visited with a specially constructed URL. This could allow an authenticated, non-administrative, user to, among others: add new users, add systems, remove clusters from conga, and view logs.
This particular issue affects luci, as included in conga, and does not affect luci otherwise.
Acknowledgements:
This issue was discovered by Radek Steiger of Red Hat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1112813?
The severity of REDHAT-BUG-1112813 is considered moderate, as it allows authenticated non-administrative users to access restricted components.
How do I fix REDHAT-BUG-1112813?
To fix REDHAT-BUG-1112813, ensure that access to the /luci/homebase and /luci/cluster components is restricted to only administrative users.
What are the potential impacts of REDHAT-BUG-1112813?
The potential impacts of REDHAT-BUG-1112813 include unauthorized access to sensitive administrative features by logged-in, non-administrative users.
Who is affected by REDHAT-BUG-1112813?
Users of the Red Hat Luci software with non-administrative access are affected by REDHAT-BUG-1112813.
Is there a workaround for REDHAT-BUG-1112813?
A workaround for REDHAT-BUG-1112813 involves implementing additional URL validation to prevent access to restricted components.