The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-09-06T21:00:00

Updated: 2024-08-06T05:39:31.642Z

Reserved: 2015-04-10T00:00:00

Link: CVE-2015-3163

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2017-09-06T21:29:00.583

Modified: 2020-03-09T18:39:15.420

Link: CVE-2015-3163

cve-icon Redhat

No data.