Vulnerabilities > Katello > Katello Installer > 0.0.1

DATE CVE VULNERABILITY TITLE RISK
2014-05-14 CVE-2013-4455 Permissions, Privileges, and Access Controls vulnerability in Katello Installer
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.
local
low complexity
katello CWE-264
2.1