CVE-2012-3503

9.8 CRITICAL
Published: August 25, 2012 Modified: April 29, 2026
View on NVD

Description

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1186.html
Source: secalert@redhat.com
Broken Link Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1187.html
Source: secalert@redhat.com
Third Party Advisory
http://secunia.com/advisories/50344
Source: secalert@redhat.com
Broken Link
http://www.securityfocus.com/bid/55140
Source: secalert@redhat.com
Broken Link Third Party Advisory VDB Entry
https://github.com/Katello/katello/pull/499
Source: secalert@redhat.com
Issue Tracking
http://rhn.redhat.com/errata/RHSA-2012-1186.html
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2012-1187.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/50344
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.securityfocus.com/bid/55140
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Third Party Advisory VDB Entry
https://github.com/Katello/katello/pull/499
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

12 reference(s) from NVD

Quick Stats

CVSS v3 Score
9.8 / 10.0
EPSS (Exploit Probability)
1.3%
80th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

theforeman redhat