Vulnerabilities > Katello

DATE CVE VULNERABILITY TITLE RISK
2018-05-01 CVE-2013-4201 Permission Issues vulnerability in Katello
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.
network
low complexity
katello CWE-275
4.3
2016-06-07 CVE-2016-3072 SQL Injection vulnerability in multiple products
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.
network
low complexity
katello redhat CWE-89
8.8
2014-11-03 CVE-2014-3712 Resource Management Errors vulnerability in Katello
Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) action parameter in the respond function in api/api_controller.rb in app/controllers/katello/, which is passed to the to_sym method.
network
low complexity
katello CWE-399
5.0
2014-05-14 CVE-2013-4455 Permissions, Privileges, and Access Controls vulnerability in Katello Installer
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.
local
low complexity
katello CWE-264
2.1
2013-03-01 CVE-2012-6116 Permissions, Privileges, and Access Controls vulnerability in Katello and Katello-Configure
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.
local
low complexity
katello CWE-264
2.1
2013-03-01 CVE-2012-5561 Information Exposure vulnerability in Katello 1.1
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.
local
low complexity
katello CWE-200
2.1