An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.
References
Link Resource
http://www.securityfocus.com/bid/106490 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14666 Issue Tracking Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2019-01-22T15:00:00

Updated: 2019-01-23T10:57:01

Reserved: 2018-07-27T00:00:00


Link: CVE-2018-14666

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-01-22T15:29:00.317

Modified: 2019-10-09T23:35:09.047


Link: CVE-2018-14666

JSON object: View

cve-icon Redhat Information

No data.