CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

theforeman

katello

8 known vulnerabilities · sorted by CVSS score

CVE-2013-4120
HIGH7.5

Katello has a Denial of Service vulnerability in API OAuth authentication

theforeman / katello
Network
Published Dec 10, 2019
CVE-2016-9595
HIGH7.3

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

theforeman / katello+2
Local
Published Jul 27, 2018
CVE-2013-0283
MEDIUM5.4

Katello: Username in Notification page has cross site scripting

theforeman / katello
Network
Published Dec 5, 2019
CVE-2018-16887
MEDIUM5.4

A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution and extraction of the anti-CSRF token of higher privileged users. Versions before 3.9.0 are vulnerable.

redhat / satellite+1
Network
Published Jan 13, 2019
CVE-2013-2101
MEDIUM5.4

Katello has multiple XSS issues in various entities

theforeman / katello+1
Network
Published Dec 3, 2019
CVE-2017-2662
MEDIUM4.3

A flaw was found in Foreman's katello plugin version 3.4.5. After setting a new role to allow restricted access on a repository with a filter (filter set on the Product Name), the filter is not respected when the actions are done via hammer using the repository id.

theforeman / katello
Network
Published Aug 22, 2018
CVE-2018-14623
MEDIUM4.3

A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is related to an incomplete fix for CVE-2016-3072. Version 3.10 and older is vulnerable.

theforeman / katello
Network
Published Dec 14, 2018
CVE-2019-14825
LOW2.7

A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.

theforeman / katello
Network
Published Nov 25, 2019