A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2662 | third party advisory issue tracking |
https://projects.theforeman.org/issues/18838 | vendor advisory |