CVE-2014-8183: Red Hat Satellite
High severity, CVSS 7.4. EPSS: 0.7% chance of exploitation in the next 30 days.
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.
Affected products
- Red Hat Satellite: version 6.0 only
- Theforeman Foreman: from 1.0, before 1.15.6 (fixed in 1.15.6)
Published 2019-08-01. Last modified 2026-06-17.