Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown

CVE-2013-4455

Disclosure Date: May 14, 2014 (last updated October 05, 2023)
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.
0
Attacker Value
Unknown

CVE-2013-2143

Disclosure Date: April 17, 2014 (last updated October 05, 2023)
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.
0
Attacker Value
Unknown

CVE-2012-5561

Disclosure Date: March 01, 2013 (last updated October 05, 2023)
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.
0
Attacker Value
Unknown

CVE-2012-6116

Disclosure Date: March 01, 2013 (last updated October 05, 2023)
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.
0
Attacker Value
Unknown

CVE-2012-3503

Disclosure Date: August 25, 2012 (last updated February 14, 2024)
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
Attacker Value
Unknown

CVE-2006-0811

Disclosure Date: February 21, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in reguser.php in Skate Board 0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters involved with the registration form.
0
Attacker Value
Unknown

CVE-2006-0809

Disclosure Date: February 21, 2006 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Skate Board 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) usern parameter in (a) sendpass.php, and the (2) usern and (3) passwd parameters and (4) sf_cookie cookie in (b) login.php and (c) logged.php.
0
Attacker Value
Unknown

CVE-2006-0810

Disclosure Date: February 21, 2006 (last updated February 22, 2025)
Unspecified vulnerability in config.php in Skate Board 0.9 allows remote authenticated administrators to execute arbitrary PHP code by causing certain variables in config.php to be modified, possibly due to XSS or direct static code injection.
0