CVE-2019-3845 - CVE House
Back to Database
Status published High CVE-2019-3845

A lack of access control was found in the message...

Vulnerability Description

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3845

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

qpid-dispatch-router
Vulnerable Versions:
fixed in Satellite >= 6.2, fixed in Satellite 6.1 - Optional, fixed in Satellite Capsule 6.1

Timeline

Official Publish: April 11th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)