First published: Fri Mar 01 2013(Updated: )
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Katello Katello | ||
Katello Katello-configure | <=1.3.2_pulpv2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.