Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-31655

Insufficient Page Authorization

XMLWordPrintable

    • None
    • None
    • None
    • Automated

      Description of problem:

      A user with no assigned roles is able to access the https://satellite.example.com/hosts/register page. This is a security concern as it allows unauthorized users to access a registration interface, which should be restricted.
       

      How reproducible:

       100%

      Is this issue a regression from an earlier version:

       NA

      Steps to Reproduce:

      1. Create a user account with no assigned roles in Satellite.

      2. Log in with this user and navigate to https://satellite.example.com/hosts/register.

      3. Observe that the page is accessible instead of displaying a "No Permission" error.

      Actual behavior:

      Users without roles can still access the /hosts/register page.

      Expected behavior:

      As the user does not have any privileges, so Permission denied should be visible for all the pages for satellite.

      Business Impact / Additional info:

       Security threat.

          There are no Sub-Tasks for this issue.

              rhn-engineering-lstejska Leos Stejskal
              rhn-support-sadas Satyajit Das
              Amol Patil Amol Patil
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: