Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24510
HistoryApr 10, 2020 - 12:56 a.m.

Authorization Bypass

2020-04-1000:56:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.007

Percentile

79.6%

spacewalk-config is vulnerable to authorization bypass. The vulnerability exists as RHN Satellite incorrectly exposed an obsolete XML-RPC API for configuring package group (comps.xml) files for channels. An authenticated user could use this flaw to gain access to arbitrary files accessible to the RHN Satellite server process, and prevent clients from performing certain yum operations.

EPSS

0.007

Percentile

79.6%

Related for VERACODE:24510