Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.