5.2
CVSSv2

CVE-2019-3845

Published: 11/04/2019 Updated: 15/10/2020
CVSS v2 Base Score: 5.2 | Impact Score: 6.4 | Exploitability Score: 5.1
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 463
Vector: AV:A/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat satellite

Vendor Advisories

Synopsis Important: katello-installer-base security and enhancement update Type/Severity Security Advisory: Important Topic An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 62 for RHEL 6 and Red Hat Satellite 62 for RHEL 7Red Hat Product Se ...
Synopsis Important: Red Hat Satellite Tools security update Type/Severity Security Advisory: Important Topic An update is now available for Satellite Tools 65Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, wh ...
Synopsis Important: katello-installer-base security and enhancement update Type/Severity Security Advisory: Important Topic An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 63 for RHEL 7Red Hat Product Security has rated this update as havin ...
Synopsis Important: katello-installer-base security and enhancement update Type/Severity Security Advisory: Important Topic An update for katello-installer-base which configures qpid-dispatch-router is now available for Red Hat Satellite 64 for RHEL 7Red Hat Product Security has rated this update as havin ...
Impact: Important Public Date: 2019-04-09 CWE: CWE-284 Bugzilla: 1684275: CVE-2019-3845 qpid-dispatch-r ...