Katello is a systems and package-management platform that operates within the Red Hat ecosystem, with a narrowly scoped product line centered on the core Katello application and its installer components. The durable signal across its vulnerability disclosures centers on information-exposure and input-handling weaknesses, particularly SQL injection and improper neutralization of special elements in queries, which reflect the data-management and query-processing demands of a centralized repository and lifecycle-management tool. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Katello over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3072HIGH Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbi | Jun 7, 2016 | 8.8 | 27 | NO | NO |
CVE-2024-4812MEDIUM A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when ope | Jun 5, 2024 | 4.8 | 16 | NO | NO |
CVE-2014-3712MEDIUM Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) acti | Nov 3, 2014 | 5.0 | 15 | NO | NO |
CVE-2013-4201MEDIUM Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions. | May 1, 2018 | 4.3 | 14 | NO | NO |
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modif | Mar 1, 2013 | 2.1 | 14 | NO | NO |
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading t | Mar 1, 2013 | 2.1 | 13 | NO | NO |
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the p | May 14, 2014 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Katello.
Media articles that mention a CVE ID that affects a product developed by Katello — matched by CVE ID, not by vendor name.