QID 998017
QID 998017: Rubygems (Rubygems) Security Update for katello (GHSA-5xv2-q475-rwrh)
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5xv2-q475-rwrh for updates and patch information.
Vendor References
- GHSA-5xv2-q475-rwrh -
github.com/advisories/GHSA-5xv2-q475-rwrh
CVEs related to QID 998017
Software Advisories
| Advisory ID | Software | Component | Link |
|---|