A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2662 Issue Tracking Third Party Advisory
https://projects.theforeman.org/issues/18838 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2018-08-22T16:00:00

Updated: 2018-08-22T15:57:01

Reserved: 2016-12-01T00:00:00


Link: CVE-2017-2662

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-08-22T16:29:01.417

Modified: 2023-02-12T23:29:39.563


Link: CVE-2017-2662

JSON object: View

cve-icon Redhat Information

No data.