Vulnerability record · CVE-2012-3503 · published 25 August 2012
CVE-2012-3503: Theforeman katello hard-coded credentials vulnerability
Theforeman · Katello
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
Description
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://rhn.redhat.com/errata/RHSA-2012-1186.html | Broken LinkThird Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1187.html | Third Party Advisory |
| http://secunia.com/advisories/50344 | Broken Link |
| http://www.securityfocus.com/bid/55140 | Broken LinkThird Party AdvisoryVDB Entry |
| https://github.com/Katello/katello/commit/7c256fef9d75029d0ffff58ff1dcda915056d3a3 | Patch |
| https://github.com/Katello/katello/pull/499 | Issue Tracking |
| http://rhn.redhat.com/errata/RHSA-2012-1186.html | Broken LinkThird Party Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1187.html | Third Party Advisory |
| http://secunia.com/advisories/50344 | Broken Link |
| http://www.securityfocus.com/bid/55140 | Broken LinkThird Party AdvisoryVDB Entry |
| https://github.com/Katello/katello/commit/7c256fef9d75029d0ffff58ff1dcda915056d3a3 | Patch |
| https://github.com/Katello/katello/pull/499 | Issue Tracking |
Track CVE-2012-3503 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-3503), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.