Home/Product/theforeman katello
Product

theforeman katello

17 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-4812
all versions
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" f
4.8MEDIUM
CVE-2013-4120
all versions
Katello has a Denial of Service vulnerability in API OAuth authentication
7.5HIGH
CVE-2013-0283
all versions
Katello: Username in Notification page has cross site scripting
5.4MEDIUM
CVE-2013-2101
all versions
Katello has multiple XSS issues in various entities
5.4MEDIUM
CVE-2019-14825
>= 3.0.0.0 and < 3.12.0.9
A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used
2.7LOW
CVE-2018-16887
< 3.9.0
A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organ
5.4MEDIUM
CVE-2018-14623
>= 3.10.0
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a m
4.3MEDIUM
CVE-2017-2662
all versions
A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository wi
4.3MEDIUM
CVE-2016-9595
< 3.4.0
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user cou
7.3HIGH
CVE-2013-4201
all versions
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system"
4.3MEDIUM
CVE-2016-3072
all versions
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katell
8.8HIGH
CVE-2014-3712
all versions
Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils fu
CVE-2013-4455
<= 0.0.17
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child P
CVE-2013-2143
<= 1.5.0-14
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles act
CVE-2012-6116
<= 1.3.2_pulpv2
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepi
CVE-2012-5561
all versions
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows
CVE-2012-3503
<= 1.0
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which cau
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin