CVE-2012-5561

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
01/03/2013
Last modified:
11/04/2025

Description

script/katello-generate-passphrase in Katello 1.1 uses world-readable permissions for /etc/katello/secure/passphrase, which allows local users to obtain the passphrase by reading the file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:katello:katello:1.1:*:*:*:*:*:*:*