Untriaged
Permalink
CVE-2023-4320
7.6 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): HIGH
- Availability impact (A): LOW
Satellite: arithmetic overflow in satellite
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.
References
Affected products
foreman
- *
Security
satellite
- ==6.13
Matching in nixpkgs
pkgs.foreman
Process manager for applications with multiple components
pkgs.emacsPackages.foreman-mode
None
-
nixos-unstable 20170725.1422
- nixpkgs-unstable 20170725.1422
- nixos-unstable-small 20170725.1422
Package maintainers
-
@zimbatm zimbatm <zimbatm@zimbatm.com>