CVE-2012-6116 describes a weak permissions vulnerability in Katello's katello-configure component, specifically affecting versions before 1.3.3.pulpv2. The vulnerability allows local users to modify the Candlepin CA certificate due to insecure permissions (666) on the Candlepin bootstrap RPM. This is a low-severity vulnerability with a CVSS score of 2.1, indicating that an attacker would need local access to the system (AV:L) and the attack complexity is low (AC:L). The potential impact is limited to modifying the certificate (I:P) without affecting confidentiality or availability. There is no evidence of active exploitation, nor is there any public exploit code available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:katello:katello:-:*:*:*:*:*:*:* | ||
<= 1.3.2_pulpv2CPE matchmatch criteria | cpe:2.3:a:katello:katello-configure:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.