CVE-2013-2143: Red Hat Network Satellite

Medium severity, CVSS 6.5. EPSS: 48.2% chance of exploitation in the next 30 days.

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

Affected products

  • Red Hat Network Satellite: affected versions not specified
  • Theforeman Katello: up to and including 1.5.0-14

Published 2014-04-17. Last modified 2026-06-16.