CVE-2013-4455: Katello Installer

Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.

Affected products

  • Katello Katello Installer: up to and including 0.0.17; version 0.0.1 only; version 0.0.2 only; version 0.0.3 only; version 0.0.4 only; version 0.0.5 only; …

Published 2014-05-14. Last modified 2026-06-16.