CVE-2019-3845
published 2019-04-11CVE-2019-3845: A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2…
PriorityP342high8CVSS 3.1
AVAACLPRLUINSUCHIHAH
EPSS
0.69%
49.0th percentile
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | qpid-dispatch-router | — | — |
| red_hat | qpid-dispatch-router | — | — |
| red_hat | qpid-dispatch-router | — | — |
| redhat | satellite | < 6.2 | 6.2 |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.0HIGHCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.2MEDIUMAV:A/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
katello-installer-base: QMF methods exposed to goferd via qdrouterd
vendor_redhat·2019-04-09·CVSS 8.0
CVE-2019-3845 [HIGH] CWE-284 katello-installer-base: QMF methods exposed to goferd via qdrouterd
katello-installer-base: QMF methods exposed to goferd via qdrouterd
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged com
GHSA
GHSA-rcf7-8mg9-v2ww: A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite
ghsa_unreviewed·2022-05-13
CVE-2019-3845 [HIGH] GHSA-rcf7-8mg9-v2ww: A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
No detection rules found.
No public exploits indexed.
2019-04-11
Published