CVE Vulnerabilities

CVE-2012-1145

Improper Authentication

Published: Jun 16, 2012 | Modified: Feb 03, 2022
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu

spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL organization when mod_wsgi is used, which allows remote attackers to cause a denial of service (/var partition disk consumption and failed updates) via a large number of package uploads.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Satellite Redhat 5.4 (including) 5.4 (including)
Red Hat Network Satellite Server v 5.4 RedHat spacewalk-backend-0:1.2.13-66.1.el6sat *

Potential Mitigations

References