{"id":"CVE-2017-2662","details":"A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.","aliases":["GHSA-cpv6-pfq6-j2v7"],"modified":"2026-08-18T11:36:18.363788Z","published":"2018-08-22T16:29:01.417Z","references":[{"type":"ADVISORY","url":"https://projects.theforeman.org/issues/18838"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2662"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/katello/katello","events":[{"introduced":"3a34a7897dbfe938e4cbe5e67c2c71e715df3b2a"},{"last_affected":"3a34a7897dbfe938e4cbe5e67c2c71e715df3b2a"}],"database_specific":{"cpe":"cpe:2.3:a:theforeman:katello:3.4.5:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.4.5"},{"last_affected":"3.4.5"}],"source":"CPE_STRING"}}],"versions":["3.4.5"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-2662.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}