katello-installer-base: QMF methods exposed to goferd via qdrouterd
Published Apr 11, 2019
8.0
HIGHCVSS 3.1
EPSS 0.68%
Description
A lack of access control was found in the message queues maintained by Satellite's QPID broker and used by katello-agent in versions before Satellite 6.2, Satellite 6.1 optional and Satellite Capsule 6.1. A malicious user authenticated to a host registered to Satellite (or Capsule) can use this flaw to access QMF methods to any host also registered to Satellite (or Capsule) and execute privileged commands.
Affected products
-
- Version fixed in Satellite 6.1 - OptionalStatusaffectedConstraints-
- Version fixed in Satellite >= 6.2StatusaffectedConstraints-
- Version fixed in Satellite Capsule 6.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Qpid-Dispatch-Router | n/a |
|
No data.
Red Hat Satellite 6.2 for RHEL 6
katello-installer-base-0:3.0.0.105-1.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
katello-installer-base-0:3.0.0.105-1.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
libwebsockets-0:2.1.0-3.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
libwebsockets-0:2.1.0-3.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
python-qpid-0:1.35.0-5.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
python-qpid-0:1.35.0-5.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
qpid-cpp-0:1.36.0-19.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
qpid-cpp-0:1.36.0-19.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
qpid-dispatch-0:0.8.0-10.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
qpid-dispatch-0:0.8.0-10.el6
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
qpid-proton-0:0.16.0-12.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
qpid-proton-0:0.16.0-12.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
satellite-0:6.2.16.1-1.0.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
satellite-0:6.2.16.1-1.0.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
tfm-rubygem-katello-0:3.0.0.171-1.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
tfm-rubygem-katello-0:3.0.0.171-1.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
tfm-rubygem-qpid_messaging-0:1.36.0-6.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 6
tfm-rubygem-qpid_messaging-0:1.36.0-6.el6sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
katello-installer-base-0:3.0.0.105-1.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
katello-installer-base-0:3.0.0.105-1.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
libwebsockets-0:2.1.0-3.el7
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
libwebsockets-0:2.1.0-3.el7
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
python-qpid-0:1.35.0-5.el7
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
python-qpid-0:1.35.0-5.el7
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
qpid-cpp-0:1.36.0-19.el7
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
qpid-cpp-0:1.36.0-19.el7
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
qpid-dispatch-0:0.8.0-16.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
qpid-dispatch-0:0.8.0-16.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
qpid-proton-0:0.16.0-12.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
qpid-proton-0:0.16.0-12.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
satellite-0:6.2.16.1-1.0.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
satellite-0:6.2.16.1-1.0.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
tfm-rubygem-katello-0:3.0.0.171-1.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
tfm-rubygem-katello-0:3.0.0.171-1.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
tfm-rubygem-qpid_messaging-0:1.36.0-6.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.2 for RHEL 7
tfm-rubygem-qpid_messaging-0:1.36.0-6.el7sat
Fixed · RHSA-2019:0734
Red Hat Satellite 6.3 for RHEL 7
katello-installer-base-0:3.4.5.35-1.el7sat
Fixed · RHSA-2019:0733
Red Hat Satellite 6.3 for RHEL 7
katello-installer-base-0:3.4.5.35-1.el7sat
Fixed · RHSA-2019:0733
Red Hat Satellite 6.3 for RHEL 7
satellite-0:6.3.5.1-1.el7sat
Fixed · RHSA-2019:0733
Red Hat Satellite 6.3 for RHEL 7
satellite-0:6.3.5.1-1.el7sat
Fixed · RHSA-2019:0733
Red Hat Satellite 6.4 for RHEL 7
katello-installer-base-0:3.7.0.19-1.el7sat
Fixed · RHSA-2019:0735
Red Hat Satellite 6.4 for RHEL 7
katello-installer-base-0:3.7.0.19-1.el7sat
Fixed · RHSA-2019:0735
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.2 for RHEL 6 | katello-installer-base-0:3.0.0.105-1.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | katello-installer-base-0:3.0.0.105-1.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | libwebsockets-0:2.1.0-3.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | libwebsockets-0:2.1.0-3.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | python-qpid-0:1.35.0-5.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | python-qpid-0:1.35.0-5.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | qpid-cpp-0:1.36.0-19.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | qpid-cpp-0:1.36.0-19.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | qpid-dispatch-0:0.8.0-10.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | qpid-dispatch-0:0.8.0-10.el6 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | qpid-proton-0:0.16.0-12.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | qpid-proton-0:0.16.0-12.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | satellite-0:6.2.16.1-1.0.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | satellite-0:6.2.16.1-1.0.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | tfm-rubygem-katello-0:3.0.0.171-1.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | tfm-rubygem-katello-0:3.0.0.171-1.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | tfm-rubygem-qpid_messaging-0:1.36.0-6.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 6 | tfm-rubygem-qpid_messaging-0:1.36.0-6.el6sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | katello-installer-base-0:3.0.0.105-1.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | katello-installer-base-0:3.0.0.105-1.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | libwebsockets-0:2.1.0-3.el7 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | libwebsockets-0:2.1.0-3.el7 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | python-qpid-0:1.35.0-5.el7 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | python-qpid-0:1.35.0-5.el7 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | qpid-cpp-0:1.36.0-19.el7 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | qpid-cpp-0:1.36.0-19.el7 | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | qpid-dispatch-0:0.8.0-16.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | qpid-dispatch-0:0.8.0-16.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | qpid-proton-0:0.16.0-12.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | qpid-proton-0:0.16.0-12.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | satellite-0:6.2.16.1-1.0.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | satellite-0:6.2.16.1-1.0.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | tfm-rubygem-foreman_theme_satellite-0:0.1.47.5-1.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | tfm-rubygem-katello-0:3.0.0.171-1.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | tfm-rubygem-katello-0:3.0.0.171-1.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | tfm-rubygem-qpid_messaging-0:1.36.0-6.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.2 for RHEL 7 | tfm-rubygem-qpid_messaging-0:1.36.0-6.el7sat | Fixed | RHSA-2019:0734 |
| Red Hat Satellite 6.3 for RHEL 7 | katello-installer-base-0:3.4.5.35-1.el7sat | Fixed | RHSA-2019:0733 |
| Red Hat Satellite 6.3 for RHEL 7 | katello-installer-base-0:3.4.5.35-1.el7sat | Fixed | RHSA-2019:0733 |
| Red Hat Satellite 6.3 for RHEL 7 | satellite-0:6.3.5.1-1.el7sat | Fixed | RHSA-2019:0733 |
| Red Hat Satellite 6.3 for RHEL 7 | satellite-0:6.3.5.1-1.el7sat | Fixed | RHSA-2019:0733 |
| Red Hat Satellite 6.4 for RHEL 7 | katello-installer-base-0:3.7.0.19-1.el7sat | Fixed | RHSA-2019:0735 |
| Red Hat Satellite 6.4 for RHEL 7 | katello-installer-base-0:3.7.0.19-1.el7sat | Fixed | RHSA-2019:0735 |
No package ranges for this CVE.
Remediation
Red Hat statement
On Red Hat Satellite 6.5, the Satellite 6.5 GA release includes a version of katello-installer-base that provides the fixes for this issue.
Red Hat mitigation
On Satellite Server follow the instructions below: * Modify /etc/qpid/qpidd.conf to add this line: acl-file=qpid_acls.acl * Create a new file: /var/lib/qpidd/.qpidd/qpid_acls.acl with content: acl allow katello_agent@QPID create queue acl allow katello_agent@QPID consume queue acl allow katello_agent@QPID access exchange acl allow katello_agent@QPID access queue acl allow katello_agent@QPID publish exchange routingkey=pulp.task acl allow katello_agent@QPID publish exchange name=qmf.default.direct acl allow katello_agent@QPID access method name=create acl deny-log katello_agent@QPID access method name=* acl deny-log katello_agent@QPID all all # allow anything else acl allow all all * As root, execute the command: # systemctl restart qpidd * In /etc/qpid-dispatch/qdrouterd.conf modify the connector: connector { name: broker host: localhost port: 5671 sasl-mechanisms: PLAIN sasl-username: katello_agent sasl-password: katello_agent role: route-container ssl-profile: client idle-timeout-seconds: 0 } * As root, execute the command: # systemctl restart qdrouterd These ACLs will prevent clients to redirect or move messages to various queues which is the nature of the CVE. All other behavior will be unchanged (acl allow all all) which is the current baseline.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:A/AC:L/Au:S/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.68% (0.00679) | 50.62th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.68% (0.00679) | 50.90th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.04% (0.00044) | 12.95th | v3 (v2023.03.01) |
| May 25, 2024 | 0.04% (0.00044) | 12.27th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 10.26th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.40% (0.01404) | 49.02th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.74% (0.02742) | 63.06th | v1 |
| Jan 6, 2022 | 2.74% (0.02742) | 62.72th | v1 |
| Jan 5, 2022 | 0.62% (0.00624) | 46.35th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (6)
- https://access.redhat.com/errata/RHSA-2019:1223 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3845 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1684275 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3845 x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-3845
- https://www.cve.org/CVERecord?id=CVE-2019-3845
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2019:1223 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-3845 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1684275 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3845 | x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-3845 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-3845 |
Change history (0)
No recorded changes yet.