CVE-2012-3503 describes a critical vulnerability in Katello 1.0 and earlier, affecting Red Hat Enterprise Linux Server and TheForeman Katello installations. The flaw stems from the installation script failing to properly generate a unique Application.config.secret_token, leading to all default installations sharing the same secret. This allows remote attackers to authenticate as any user to the CloudForms System Engine web interface by crafting a cookie with the known default secret. The vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. It is classified under CWE-798 (Use of Hard-coded Credentials). While there is no evidence of active exploitation (not in KEV), and no public exploit code is available on Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:theforeman:katello:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.