CVE-2013-2143: Red Hat Network Satellite
Medium severity, CVSS 6.5. EPSS: 48.2% chance of exploitation in the next 30 days.
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
Affected products
- Red Hat Network Satellite: affected versions not specified
- Theforeman Katello: up to and including 1.5.0-14
Published 2014-04-17. Last modified 2026-06-16.