Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Katello Project

First CVE: Mar 1, 2013Active for: 13 yearsTotal CVEs: 7

Katello Project maintains a systems management and repository management tool focused on lifecycle and content management for enterprise Linux environments. The recurring vulnerability signal centers on cross-site scripting weaknesses in its web interface, reflecting the input-handling challenges typical of browser-facing administrative consoles. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
Bottom 1%
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
4.2
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Katello Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2013
13 years ago
Most Recent CVE
Jun 5, 2024
779 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-3072HIGH
Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbi
Jun 7, 20168.827NONO
CVE-2024-4812MEDIUM
A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when ope
Jun 5, 20244.816NONO
CVE-2014-3712MEDIUM
Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) acti
Nov 3, 20145.015NONO
CVE-2013-4201MEDIUM
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.
May 1, 20184.314NONO
CVE-2012-6116LOW
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modif
Mar 1, 20132.114NONO
CVE-2012-5561LOW
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading t
Mar 1, 20132.113NONO
CVE-2013-4455LOW
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the p
May 14, 20142.111NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
43%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (42.9%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None2 (28.6%)
Unknown4 (57.1%)
Required1 (14.3%)
Privileges Required
Low2 (28.6%)
High1 (14.3%)
None0 (0.0%)
Unknown4 (57.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Katello Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Katello Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Katello Project's Products

View all 1 CNAs →

Top CWEs