CVE-2013-2143
Red Hat Satellite and Katello < 1.5.0-14 - Authenticated Privilege Escalation via users/update_roles
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2013-2143.
PoCs published by Metasploit, including Metasploit module auxiliary/admin/http/katello_satellite_priv_esc.
AI-analyzed exploit summary This Metasploit module exploits a missing authorization vulnerability in Katello and Red Hat Satellite (CVE-2013-2143) by escalating a user's privileges to administrator via the 'update_roles' action. It authenticates, retrieves a CSRF token, and sends a crafted PUT request to modify the user's role.
Description
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
Exploits (2)
This Metasploit module exploits a missing authorization vulnerability in Katello and Red Hat Satellite (CVE-2013-2143) by escalating a user's privileges to administrator via the 'update_roles' action. It authenticates, retrieves a CSRF token, and sends a crafted PUT request to modify the user's role.
This Metasploit module exploits a missing authorization vulnerability in Katello and Red Hat Satellite (CVE-2013-2143) by escalating a user's privileges to administrator via the 'update_roles' action. It authenticates, retrieves a CSRF token, and sends a PUT request to modify the user's role.