REDHAT-BUG-1434106: Low severity foreman vulnerability
Brad Buckingham of Red Hat reports:
After settings a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
External reference: http://projects.theforeman.org/issues/18838
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1434106?
The severity of REDHAT-BUG-1434106 is considered to be moderate due to the potential for unauthorized access restrictions to be bypassed.
How do I fix REDHAT-BUG-1434106?
To fix REDHAT-BUG-1434106, apply the latest updates provided by Red Hat for the Foreman application.
What does REDHAT-BUG-1434106 affect?
REDHAT-BUG-1434106 affects the Red Hat Foreman application with repository access filters.
Who reported the vulnerability REDHAT-BUG-1434106?
REDHAT-BUG-1434106 was reported by Brad Buckingham of Red Hat.
What is the nature of the issue in REDHAT-BUG-1434106?
The issue in REDHAT-BUG-1434106 is that repository access filters based on product names are not respected when using specific command-line actions.