Katello
Sign in to watchby Theforeman
Source repositories
CVEs (9)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2012-3503 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2012 | The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token. | |
| CVE-2013-2143 | 0.08 | — | 0.61 | Apr 17, 2014 | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account. | ||
| CVE-2014-0183 | 0.00 | — | 0.00 | Jan 2, 2020 | Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. | ||
| CVE-2013-4120 | 0.00 | — | 0.01 | Dec 10, 2019 | Katello has a Denial of Service vulnerability in API OAuth authentication | ||
| CVE-2013-0283 | 0.00 | — | 0.00 | Dec 5, 2019 | Katello: Username in Notification page has cross site scripting | ||
| CVE-2013-2101 | 0.00 | — | 0.00 | Dec 3, 2019 | Katello has multiple XSS issues in various entities | ||
| CVE-2014-3712 | 0.00 | — | 0.01 | Nov 3, 2014 | Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) action parameter in the respond function in api/api_controller.rb in app/controllers/katello/, which is passed to the to_sym method. | ||
| CVE-2012-6116 | 0.00 | — | 0.00 | Mar 1, 2013 | modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file. | ||
| CVE-2012-5561 | 0.00 | — | 0.00 | Mar 1, 2013 | script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file. |