VDB
Sign up
CRITICAL9.8

GHSA-5xv2-q475-rwrh

Katello uses hard coded credential

Quick fix

GHSA-5xv2-q475-rwrh — katello: upgrade to the fixed version with the command below.

bundle update katello

Details

The installation script in Katello 1.0 and earlier does not properly generate the `Application.config.secret_token` value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default `secret_token`.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/katello
Introduced in: 0Fixed in: 1.0.6
Fixbundle update katello
RubyGems/katello
Introduced in: 1.1.0Fixed in: 1.1.7
Fixbundle update katello

References