It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
2018-07-27T13:29:00.333
2024-11-21T03:31:58.013
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | spacewalk | - | Yes |
Application | redhat | satellite | 5.6 | Yes |
Application | redhat | satellite | 5.7 | Yes |