Katello Project maintains a systems management and repository management tool focused on lifecycle and content management for enterprise Linux environments. The recurring vulnerability signal centers on cross-site scripting weaknesses in its web interface, reflecting the input-handling challenges typical of browser-facing administrative consoles. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Katello Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-3072HIGH Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbi | Jun 7, 2016 | 8.8 | 27 | NO | NO |
CVE-2024-4812MEDIUM A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Description" field of a user. This code can be executed when ope | Jun 5, 2024 | 4.8 | 16 | NO | NO |
CVE-2014-3712MEDIUM Katello allows remote attackers to cause a denial of service (memory consumption) via the (1) mode parameter in the setup_utils function in content_search_controller.rb or (2) acti | Nov 3, 2014 | 5.0 | 15 | NO | NO |
CVE-2013-4201MEDIUM Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions. | May 1, 2018 | 4.3 | 14 | NO | NO |
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modif | Mar 1, 2013 | 2.1 | 14 | NO | NO |
script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading t | Mar 1, 2013 | 2.1 | 13 | NO | NO |
Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the p | May 14, 2014 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Katello Project.
Media articles that mention a CVE ID that affects a product developed by Katello Project — matched by CVE ID, not by vendor name.