CVE-2012-6116

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
01/03/2013
Last modified:
11/04/2025

Description

modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:katello:katello:-:*:*:*:*:*:*:*
cpe:2.3:a:katello:katello-configure:*:*:*:*:*:*:*:* 1.3.2_pulpv2 (including)