First published: Mon Aug 31 2020(Updated: )
A account takeover flaw was found in Red Hat Satellite 6.7.2 onward, a potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Satellite with Embedded Oracle | >=6.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1873926 is considered high due to the potential for account takeover.
To fix REDHAT-BUG-1873926, update your Red Hat Satellite software to the latest patched version.
REDHAT-BUG-1873926 affects users of Red Hat Satellite 6.7.2 and later who utilize external authentication sources.
REDHAT-BUG-1873926 is classified as an account takeover vulnerability.
Yes, an external attacker with proper authentication can exploit REDHAT-BUG-1873926 to take over existing user accounts.