CVE-2014-8168
published 2017-08-28CVE-2014-8168: Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
PriorityP423medium6.1CVSS 3.0
AVLACLPRLUINSUCLIHAN
EPSS
0.27%
19.1th percentile
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite: Local user can access MongoDB and delete database
vendor_redhat·2015-02-18·CVSS 6.1
CVE-2014-8168 [MEDIUM] CWE-862 Satellite: Local user can access MongoDB and delete database
Satellite: Local user can access MongoDB and delete database
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
A missing authorization flaw was found in Red Hat Satellite. This flaw allows a malicious local user to access MongoDB on the Satellite server and delete the pulp_database, leading to corruption in the Satellite database. The highest threat from this vulnerability is confidentiality, integrity, and system availability.
Statement: Red Hat Satellite should not be accessed locally by untrusted users, thus this flaw is considered as a moderate impact only. Satellite is removing MongoDB support in future product releases. Public announcement: https://www.redhat.com/en/blog/red-hat-satellite-standardize-postgresql-backend
Mitigation: Mitigation for th
GHSA
GHSA-5jjq-h8hf-79hx: Red Hat Satellite 6 allows local users to access mongod and delete pulp_database
ghsa_unreviewed·2022-05-17
CVE-2014-8168 [MEDIUM] CWE-284 GHSA-5jjq-h8hf-79hx: Red Hat Satellite 6 allows local users to access mongod and delete pulp_database
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
No detection rules found.
No public exploits indexed.
2017-08-28
Published