2.1
CVSSv2

CVE-2013-4455

Published: 14/05/2014 Updated: 15/05/2014
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Katello Installer prior to 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

katello katello installer 0.0.7

katello katello installer 0.0.6

katello katello installer 0.0.5

katello katello installer 0.0.4

katello katello installer 0.0.15

katello katello installer 0.0.14

katello katello installer 0.0.13

katello katello installer 0.0.12

katello katello installer 0.0.16

katello katello installer 0.0.11

katello katello installer 0.0.9

katello katello installer 0.0.2

katello katello installer

katello katello installer 0.0.10

katello katello installer 0.0.8

katello katello installer 0.0.3

katello katello installer 0.0.1

Vendor Advisories

Katello Installer before 0018 uses world-readable permissions for /etc/pki/tls/private/katello-nodekey when deploying a child Pulp node, which allows local users to obtain the private key by reading the file ...