CVE-2012-3503

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
25/08/2012
Last modified:
11/04/2025

Description

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:theforeman:katello:*:*:*:*:*:*:*:* 1.0 (including)
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*