CVE-2012-3503

critical
Published 2022-05-17 · Modified 2024-04-11
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.5
VIR risk
9.8

Description

Katello uses hard coded credential

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/Katello/katello/commit/7c256fef9d75029d0ffff58ff1dcda915056d3a3

OS impact

OSVersionStatusFixed in
redhat rhel6.0affected

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemskatello<~> 1.0.6~> 1.0.6
ruby RubyGemskatello<1.0.61.0.6
ruby RubyGemskatello>=1.1.0,<1.1.71.1.7

Application impact

VendorProductVersionsFixed
theforemankatello{"endIncluding":"1.0"}

References

CWEs

CWE-798

Verify integrity in audit chain (admin only). AS-IS.