ZeroHour

CVE-2020-14380

CVSS 3.1
7.5 high
EPSS
<1%p54
Published
()
Modified
Description

An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authentication source (SSO or Open ID) can claim the privileges of already existing local users of Satellite.

Vendors
redhat
Products
satellite
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.