CVE-2012-6116
01.03.2013, 05:40
modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.Enginsight
Vendor | Product | Version |
---|---|---|
katello | katello | - |
katello | katello-configure | 𝑥 ≤ 1.3.2_pulpv2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References