Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2016-3072
Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
0
Attacker Value
Unknown
CVE-2014-3712
Disclosure Date: November 03, 2014 (last updated October 05, 2023)
Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) action parameter in the respond function in api/api_controller.rb in app/controllers/katello/, which is passed to the to_sym method.
0
Attacker Value
Unknown
CVE-2013-4455
Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.
0
Attacker Value
Unknown
CVE-2013-2143
Disclosure Date: April 17, 2014 (last updated October 05, 2023)
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
0
Attacker Value
Unknown
CVE-2012-5561
Disclosure Date: March 01, 2013 (last updated October 05, 2023)
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.
0
Attacker Value
Unknown
CVE-2012-6116
Disclosure Date: March 01, 2013 (last updated October 05, 2023)
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.
0
Attacker Value
Unknown
CVE-2012-3503
Disclosure Date: August 25, 2012 (last updated February 14, 2024)
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
0