First published: Sat Aug 25 2012(Updated: )
The installation script in Katello 1.0 and earlier does not properly generate the `Application.config.secret_token` value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default `secret_token`.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Katello Katello | <=1.0 | |
Theforeman Katello | <=1.0 | |
Redhat Enterprise Linux Server | =6.0 | |
rubygems/katello | >=1.1.0<1.1.7 | 1.1.7 |
rubygems/katello | <1.0.6 | 1.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.