MidnightBSD

Advisories for katello

CVE-2012-6116 LOW

modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
katello katello -
katello katello-configure *
CVE-2013-4201 MEDIUM

Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-275,

Products Affected

Vendor Product Version
katello katello -
CVE-2013-4455 LOW

Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.

CVSS 2.0

Severity: LOW

Problem Type: CWE-264,

Products Affected

Vendor Product Version
katello katello_installer 0.0.2
katello katello_installer 0.0.9
katello katello_installer 0.0.12
katello katello_installer 0.0.5
katello katello_installer *
katello katello_installer 0.0.1
katello katello_installer 0.0.6
katello katello_installer 0.0.14
katello katello_installer 0.0.7
katello katello_installer 0.0.8
katello katello_installer 0.0.13
katello katello_installer 0.0.4
katello katello_installer 0.0.3
katello katello_installer 0.0.15
katello katello_installer 0.0.16
katello katello_installer 0.0.10
katello katello_installer 0.0.11
CVE-2014-3712 MEDIUM

Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) action parameter in the respond function in api/api_controller.rb in app/controllers/katello/, which is passed to the to_sym method.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-399,

Products Affected

Vendor Product Version
katello katello -
CVE-2016-3072 MEDIUM

Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-89,

Products Affected

Vendor Product Version
redhat satellite 6.1
katello katello -