Unrated severityNVD Advisory· Published Mar 1, 2013· Updated Apr 29, 2026
CVE-2012-6116
CVE-2012-6116
Description
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.
Affected products
2- cpe:2.3:a:katello:katello:-:*:*:*:*:*:*:*
- cpe:2.3:a:katello:katello-configure:*:*:*:*:*:*:*:*Range: <=1.3.2_pulpv2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5News mentions
0No linked articles in our index yet.