CVE-2020-14380
published 2021-06-02CVE-2020-14380: An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication…
PriorityP343high7.5CVSS 3.1
AVNACHPRLUINSUCHIHAH
EPSS
0.79%
52.2th percentile
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Satellite: Local user impersonation by Single sign-on (SSO) user leads to account takeover
vendor_redhat·2020-08-31·CVSS 7.5
CVE-2020-14380 [HIGH] CWE-287 Satellite: Local user impersonation by Single sign-on (SSO) user leads to account takeover
Satellite: Local user impersonation by Single sign-on (SSO) user leads to account takeover
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.
Red Hat Satellite's external authentication component is vulnerable to a full account takeover flaw. This flaw allows an attacker with an authenticated account on Single sign-on (SSO) to gain elevated privileges of existing local users. This issue only affects users who have configured Satellite to use Apache SSO or Open ID Connect external authentication sources, and that have not disabled the auto-creation of users on login. The highest threat from
GHSA
GHSA-j9wh-q5x6-q8gp: An account takeover flaw was found in Red Hat Satellite 6
ghsa_unreviewed·2022-05-24
CVE-2020-14380 [HIGH] CWE-287 GHSA-j9wh-q5x6-q8gp: An account takeover flaw was found in Red Hat Satellite 6
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.
No detection rules found.
No public exploits indexed.
2021-06-02
Published