Lucene search

K
cvelistRedhatCVELIST:CVE-2013-2143
HistoryApr 17, 2014 - 2:00 p.m.

CVE-2013-2143

2014-04-1714:00:00
redhat
www.cve.org

6.4 Medium

AI Score

Confidence

Low

0.748 High

EPSS

Percentile

98.2%

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

6.4 Medium

AI Score

Confidence

Low

0.748 High

EPSS

Percentile

98.2%