Lucene search

K
redhatcveRedhat.comRH:CVE-2020-14380
HistoryAug 31, 2020 - 4:27 a.m.

CVE-2020-14380

2020-08-3104:27:43
redhat.com
access.redhat.com
19

EPSS

0.001

Percentile

35.6%

Red Hat Satellite’s external authentication component is vulnerable to a full account takeover flaw. This flaw allows an attacker with an authenticated account on Single sign-on (SSO) to gain elevated privileges of existing local users. This issue only affects users who have configured Satellite to use Apache SSO or Open ID Connect external authentication sources, and that have not disabled the auto-creation of users on login. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Mitigation

This issue can be mitigated by disabling the external login if a Satellite user has their authentication set to INTERNAL.

EPSS

0.001

Percentile

35.6%