Improper authorization in Foreman - CVE-2018-14666
Published: January 8, 2019 / Updated: June 21, 2023
Foreman
Detailed vulnerability description
The vulnerability allows a remote high-privileged attacker to bypass authorization on the target system.
The vulnerability exists due to improper authorization in the Smart Class feature of Foreman. A remote attacker can bypass authorization to change configuration of any host registered in Satellite, independent of the organization the host belongs to.