First published: Fri Feb 13 2015(Updated: )
In Red Hat Satellite, the MongoDB database can be accessed by any malicious local user of the Satellite server and pulp_database content can be modified or deleted. Embedded MongoDB was introduced in Satellite 6.0 onward therefore, all the current Satellite active versions are affected by the flaw.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite with Embedded Oracle | >=6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1192249 is considered critical due to unauthorized access to the MongoDB database.
To fix REDHAT-BUG-1192249, apply the latest security patches provided by Red Hat for Satellite.
All active versions of Red Hat Satellite starting from version 6.0 are affected by REDHAT-BUG-1192249.
REDHAT-BUG-1192249 involves an embedded MongoDB database used by Red Hat Satellite.
No, REDHAT-BUG-1192249 can only be exploited by malicious local users with access to the Satellite server.