It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2017:1259 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/98569 | vdb entry third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7470 | issue tracking third party advisory |