Описание
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
Ссылки
- Broken LinkThird Party Advisory
- Third Party Advisory
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Patch
- Issue Tracking
- Broken LinkThird Party Advisory
- Third Party Advisory
- Broken Link
- Broken LinkThird Party AdvisoryVDB Entry
- Patch
- Issue Tracking
Уязвимые конфигурации
EPSS
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
Связанные уязвимости
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
EPSS
9.8 Critical
CVSS3
6.5 Medium
CVSS2