Known Vulnerabilities for Katello by Theforeman
Listed below are 9 of the newest known vulnerabilities associated with "Katello" by "Theforeman".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-14825 json | A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials ... | 2.7 - LOW | 2019-11-25 | 2023-02-12 |
| CVE-2018-16887 json | A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit ... | 5.4 - MEDIUM | 2019-01-13 | 2019-05-14 |
| CVE-2018-14623 json | A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to forc... | 4.3 - MEDIUM | 2018-12-14 | 2023-02-12 |
| CVE-2017-2662 json | A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a reposito... | 4.3 - MEDIUM | 2018-08-22 | 2023-02-12 |
| CVE-2016-9595 json | A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local use... | 5.5 - MEDIUM | 2018-07-27 | 2023-11-07 |
| CVE-2013-4120 json | Katello has a Denial of Service vulnerability in API OAuth authentication | 7.5 - HIGH | 2019-12-10 | 2019-12-10 |
| CVE-2013-2143 json | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_role... | 6.5 - MEDIUM | 2014-04-17 | 2021-07-16 |
| CVE-2013-2101 json | Katello has multiple XSS issues in various entities | 5.4 - MEDIUM | 2019-12-03 | 2023-02-13 |
| CVE-2013-0283 json | Katello: Username in Notification page has cross site scripting | 5.4 - MEDIUM | 2019-12-05 | 2019-12-09 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Theforeman | Katello | 3.9.1 | |||
| Application | Theforeman | Katello | 3.9.0 | |||
| Application | Theforeman | Katello | 3.9.0 | |||
| Application | Theforeman | Katello | 3.9.0 | |||
| Application | Theforeman | Katello | 3.8.1 | |||
| Application | Theforeman | Katello | 3.8.0 | |||
| Application | Theforeman | Katello | 3.8.0 | |||
| Application | Theforeman | Katello | 3.8.0 | |||
| Application | Theforeman | Katello | 3.7.1.1 | |||
| Application | Theforeman | Katello | 3.7.0 | |||
| Application | Theforeman | Katello | 3.7.0 | |||
| Application | Theforeman | Katello | 3.7.0 | |||
| Application | Theforeman | Katello | 3.6.0.1 | |||
| Application | Theforeman | Katello | 3.6.0 | |||
| Application | Theforeman | Katello | 3.6.0 | |||
| Application | Theforeman | Katello | 3.6.0 | |||
| Application | Theforeman | Katello | 3.5.2 | |||
| Application | Theforeman | Katello | 3.5.1.1 | |||
| Application | Theforeman | Katello | 3.5.1 | |||
| Application | Theforeman | Katello | 3.5.0.1 |