CVE Vulnerabilities

CVE-2012-5603

Published: Jan 04, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
5.5 LOW
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users settings via unspecified vectors related to the consumer UUID of a system.

Affected Software

NameVendorStart VersionEnd Version
CloudformsRedhat*1.0 (including)
CloudForms for RHEL 6RedHatcandlepin-0:0.7.8.1-1.el6cf*
CloudForms for RHEL 6RedHatgofer-0:0.66.1-2.el6cf*
CloudForms for RHEL 6RedHatgrinder-0:0.0.150-1.el6cf*
CloudForms for RHEL 6RedHatkatello-0:1.1.12-22.el6cf*
CloudForms for RHEL 6RedHatkatello-agent-0:1.1.2-1.el6cf*
CloudForms for RHEL 6RedHatkatello-certs-tools-0:1.1.8-1.el6cf*
CloudForms for RHEL 6RedHatkatello-cli-0:1.1.8-12.el6cf*
CloudForms for RHEL 6RedHatkatello-cli-tests-0:1.1.5-2.el6cf*
CloudForms for RHEL 6RedHatkatello-configure-0:1.1.9-12.el6cf*
CloudForms for RHEL 6RedHatkatello-selinux-0:1.1.1-2.el6cf*
CloudForms for RHEL 6RedHatpulp-0:1.1.14-1.el6cf*
CloudForms for RHEL 6RedHatquartz-0:2.1.5-4.el6cf*
CloudForms for RHEL 6RedHatrubygem-apipie-rails-0:0.0.11-3.el6cf*
CloudForms Tools for RHEL 5RedHatgofer-0:0.66.1-2.el5*
CloudForms Tools for RHEL 5RedHatkatello-agent-0:1.1.2-1.el5*
Red Hat Subscription Asset Manager 1.2RedHatapache-commons-codec-0:1.7-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatapache-mime4j-0:0.6-4_redhat_1.ep6.el6.1*
Red Hat Subscription Asset Manager 1.2RedHatcandlepin-0:0.7.23-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatelasticsearch-0:0.19.9-5.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-0:1.2.1-15h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-certs-tools-0:1.2.1-1h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-cli-0:1.2.1-12h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-configure-0:1.2.3-3h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-selinux-0:1.2.1-2h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatlucene3-0:3.6.1-10h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatpuppet-0:2.6.17-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatquartz-0:2.1.5-4.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-activesupport-1:3.0.10-10.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-apipie-rails-0:0.0.12-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-ldap_fluff-0:0.1.3-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-mail-0:2.3.0-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rack-1:1.3.0-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-ruby_parser-0:2.0.4-6.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatsigar-0:1.6.5-0.12.git58097d9h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatsnappy-java-0:1.0.4-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatthumbslug-0:0.0.28-1.el6_3*

References