A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
Metrics
No CVSS v4.0
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Attack Vector Adjacent Network
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
Access Vector Adjacent Network
Access Complexity Low
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
AV:A/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Redhat |
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat Enterprise Virtualization 2 | |||
gofer | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
katello-host-tools | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
pulp | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
pulp-rpm | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-isodate | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
qpid-proton | cpe:/o:redhat:enterprise_linux:7::hypervisor | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
Red Hat Satellite 6 | |||
foreman | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
future | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
gofer | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
katello-host-tools | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
openscap | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
pulp | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
pulp-puppet | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
pulp-rpm | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
puppet-agent | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-argcomplete | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-beautifulsoup4 | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-hashlib | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-isodate | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-psutil | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
python-uuid | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
qpid-proton | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
rubygem-foreman_scap_client | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
rubygem-json | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
rubygems | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
satellite | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-ror52 | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-ror52-rubygem-mime-types | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-ror52-rubygem-mime-types-data | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-ror52-rubygem-multi_json | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-apipie-bindings | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-awesome_print | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-clamp | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-domain_name | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-fast_gettext | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_csv | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_admin | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_ansible | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_bootdisk | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_discovery | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_docker | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_openscap | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_remote_execution | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_tasks | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_templates | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_foreman_virt_who_configure | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hammer_cli_katello | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-hashie | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-highline | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-http-cookie | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-little-plugger | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-locale | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-logging | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-netrc | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-oauth | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-powerbar | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-rest-client | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-unf | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-unf_ext | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-unicode | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tfm-rubygem-unicode-display_width | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
tracer | cpe:/a:redhat:rhel_satellite_tools:6.5::el5 | RHSA-2019:1223 | 2019-05-14T00:00:00Z |
Red Hat Satellite 6.2 for RHEL 6 | |||
katello-installer-base-0:3.0.0.105-1.el6sat | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
libwebsockets-0:2.1.0-3.el6 | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
python-qpid-0:1.35.0-5.el6 | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-cpp-0:1.36.0-19.el6 | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-dispatch-0:0.8.0-10.el6 | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-proton-0:0.16.0-12.el6sat | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
satellite-0:6.2.16.1-1.0.el6sat | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el6sat | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-katello-0:3.0.0.171-1.el6sat | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-qpid_messaging-0:1.36.0-6.el6sat | cpe:/a:redhat:satellite:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
katello-installer-base-0:3.0.0.105-1.el6sat | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
libwebsockets-0:2.1.0-3.el6 | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
python-qpid-0:1.35.0-5.el6 | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-cpp-0:1.36.0-19.el6 | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-dispatch-0:0.8.0-10.el6 | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-proton-0:0.16.0-12.el6sat | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
satellite-0:6.2.16.1-1.0.el6sat | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el6sat | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-katello-0:3.0.0.171-1.el6sat | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-qpid_messaging-0:1.36.0-6.el6sat | cpe:/a:redhat:satellite_capsule:6.1::el6 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
Red Hat Satellite 6.2 for RHEL 7 | |||
katello-installer-base-0:3.0.0.105-1.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
libwebsockets-0:2.1.0-3.el7 | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
python-qpid-0:1.35.0-5.el7 | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-cpp-0:1.36.0-19.el7 | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-dispatch-0:0.8.0-16.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-proton-0:0.16.0-12.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
satellite-0:6.2.16.1-1.0.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-katello-0:3.0.0.171-1.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-qpid_messaging-0:1.36.0-6.el7sat | cpe:/a:redhat:satellite:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
katello-installer-base-0:3.0.0.105-1.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
libwebsockets-0:2.1.0-3.el7 | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
python-qpid-0:1.35.0-5.el7 | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-cpp-0:1.36.0-19.el7 | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-dispatch-0:0.8.0-16.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
qpid-proton-0:0.16.0-12.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
satellite-0:6.2.16.1-1.0.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-katello-0:3.0.0.171-1.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
tfm-rubygem-qpid_messaging-0:1.36.0-6.el7sat | cpe:/a:redhat:satellite_capsule:6.2::el7 | RHSA-2019:0734 | 2019-04-09T00:00:00Z |
Red Hat Satellite 6.3 for RHEL 7 | |||
katello-installer-base-0:3.4.5.35-1.el7sat | cpe:/a:redhat:satellite:6.3::el7 | RHSA-2019:0733 | 2019-04-09T00:00:00Z |
satellite-0:6.3.5.1-1.el7sat | cpe:/a:redhat:satellite:6.3::el7 | RHSA-2019:0733 | 2019-04-09T00:00:00Z |
katello-installer-base-0:3.4.5.35-1.el7sat | cpe:/a:redhat:satellite_capsule:6.3::el7 | RHSA-2019:0733 | 2019-04-09T00:00:00Z |
satellite-0:6.3.5.1-1.el7sat | cpe:/a:redhat:satellite_capsule:6.3::el7 | RHSA-2019:0733 | 2019-04-09T00:00:00Z |
Red Hat Satellite 6.4 for RHEL 7 | |||
katello-installer-base-0:3.7.0.19-1.el7sat | cpe:/a:redhat:satellite:6.4::el7 | RHSA-2019:0735 | 2019-04-09T00:00:00Z |
katello-installer-base-0:3.7.0.19-1.el7sat | cpe:/a:redhat:satellite_capsule:6.4::el7 | RHSA-2019:0735 | 2019-04-09T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2019-04-11T14:31:40
Updated: 2024-08-04T19:19:18.596Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3845
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-04-11T15:29:00.510
Modified: 2024-11-21T04:42:41.407
Link: CVE-2019-3845
Redhat