CVE-2014-8183: Red Hat Satellite

High severity, CVSS 7.4. EPSS: 0.7% chance of exploitation in the next 30 days.

It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

Affected products

  • Red Hat Satellite: version 6.0 only
  • Theforeman Foreman: from 1.0, before 1.15.6 (fixed in 1.15.6)

Published 2019-08-01. Last modified 2026-06-17.