It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
redhat spacewalk - |
||
redhat satellite 5.7 |
||
redhat satellite 5.6 |