CVE-2013-2143

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
17/04/2014
Last modified:
12/04/2025

Description

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:network_satellite:-:*:*:*:*:*:*:*
cpe:2.3:a:theforeman:katello:*:*:*:*:*:*:*:* 1.5.0-14 (including)