CVE-2017-2662: Theforeman Katello
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.
Affected products
- Theforeman Katello: version 3.4.5 only
Published 2018-08-22. Last modified 2026-06-17.