Back

HIGH

katello-installer-base: QMF methods exposed to goferd via qdrouterd

Published Apr 11, 2019

Description

A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.

Affected products

Remediation

Red Hat statement

On Red Hat Satellite 6.5, the Satellite 6.5 GA release includes a version of katello-installer-base that provides the fixes for this issue.

Red Hat mitigation

On Satellite Server follow the instructions below: * Modify /etc/qpid/qpidd.conf to add this line: acl-file=qpid_acls.acl * Create a new file: /var/lib/qpidd/.qpidd/qpid_acls.acl with content: acl allow katello_agent@QPID create queue acl allow katello_agent@QPID consume queue acl allow katello_agent@QPID access exchange acl allow katello_agent@QPID access queue acl allow katello_agent@QPID publish exchange routingkey=pulp.task acl allow katello_agent@QPID publish exchange name=qmf.default.direct acl allow katello_agent@QPID access method name=create acl deny-log katello_agent@QPID access method name=* acl deny-log katello_agent@QPID all all # allow anything else acl allow all all * As root, execute the command: # systemctl restart qpidd * In /etc/qpid-dispatch/qdrouterd.conf modify the connector: connector { name: broker host: localhost port: 5671 sasl-mechanisms: PLAIN sasl-username: katello_agent sasl-password: katello_agent role: route-container ssl-profile: client idle-timeout-seconds: 0 } * As root, execute the command: # systemctl restart qdrouterd These ACLs will prevent clients to redirect or move messages to various queues which is the nature of the CVE. All other behavior will be unchanged (acl allow all all) which is the current baseline.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 11, 2019
Updated Aug 4, 2024
Reserved Jan 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 9, 2019