← Vulnerability feed

Vulnerability record · CVE-2013-2143 · published 17 April 2014

CVE-2013-2143: Katello and Red Hat Satellite missing authorization in update_roles

Redhat · Network Satellite

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action. A remote authenticated user can therefore change a user account to an administrator account, escalating their own or another account's privileges.

6.5 CVSS 2.0 Medium EPSS 48% · top 1.2% CWE-20 · Improper input validation
6.5CVSS 2.0 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityA remotely reachable missing-authorization flaw with public exploit code and very high EPSS, though it requires an authenticated account and is not in KEV.

What it is

The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action. A remote authenticated user can therefore change a user account to an administrator account, escalating their own or another account's privileges.

Impact

An attacker with a low-privileged authenticated account gains administrator privileges on the affected Katello or Satellite instance. That grants full control over the management platform and the systems it manages.

Attack surface

Reached over the network through the users controller update_roles action; the attacker must already be authenticated but no user interaction is required. The CVSS vector AV:N/AC:L/Au:S confirms network reachability with single authentication.

Exploitation

Public exploit code exists (Exploit-DB 32515, Packet Storm, SecurityFocus BID 66434), and EPSS is 0.48221 (98.8th percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • Upgrade Katello to a version later than 1.5.0-14 and apply the corresponding Red Hat Satellite update.
  • Restrict network access to the Katello/Satellite web interface to trusted administrators.
  • Audit user accounts and roles for unauthorized administrator assignments.
  • Enforce least privilege and review who holds authenticated accounts on the platform.

Detection

  • Monitor audit logs for update_roles requests that change a user to an administrator role.
  • Alert on role or privilege changes made by accounts that are not designated administrators.
  • Review web server logs for POST requests to the users controller update_roles endpoint from unexpected sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2143 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-3503Theforeman katello hard-coded credentials vulnerabilityThe installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…EPSS 3.0%7.5CVE-2013-4120Theforeman katello uncontrolled resource consumption vulnerabilityKatello has a Denial of Service vulnerability in API OAuth authenticationEPSS 1.3%7.5CVE-2014-8162Redhat network satellite vulnerabilityXML external entity (XXE) in the RPC interface in Spacewalk and Red Hat Network (RHN) Satellite 5.7 and earlier allows remote attackers to read arbit…EPSS 2.7%7.5CVE-2013-4480Redhat network satellite exposure of resource to wrong sphere vulnerabilityRed Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attac…EPSS 2.1%6.5CVE-2011-1594Redhat network satellite open redirect vulnerabilityA flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…EPSS 1.5%5.5CVE-2016-9595Theforeman katello link following vulnerabilityA flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this fla…EPSS 0.40%5.5CVE-2011-2920Redhat network satellite cross-site scripting vulnerabilityA flaw was found in Spacewalk and Red Hat Network Satellite. This cross-site scripting (XSS) vulnerability allows a remote attacker to inject arbitra…EPSS 2.0%5.4CVE-2013-0283Theforeman katello cross-site scripting vulnerabilityKatello: Username in Notification page has cross site scriptingEPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2013-2143), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.