QID 998017

QID 998017: Rubygems (Rubygems) Security Update for katello (GHSA-5xv2-q475-rwrh)

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Github security advisory GHSA-5xv2-q475-rwrh for updates and patch information.
    Vendor References

    CVEs related to QID 998017

    Software Advisories
    Advisory ID Software Component Link