Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.
Weaknesses in this category are related to improper assignment or handling of permissions.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=991318 | issue tracking vendor advisory |