CVE-2012-5603
proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the…
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the "consumer UUID" of a system.
- CVSS 2.0
- 5.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- redhat/cloudforms
- Source
- secalert@redhat.com
References
- http://osvdb.org/88140
- http://osvdb.org/88142
- http://rhn.redhat.com/errata/RHSA-2012-1543.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0544.html
- http://secunia.com/advisories/51472Vendor Advisory
- http://www.securityfocus.com/bid/56819
- https://bugzilla.redhat.com/show_bug.cgi?id=882129
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80549
- http://osvdb.org/88140
- http://osvdb.org/88142
- http://rhn.redhat.com/errata/RHSA-2012-1543.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0544.html
- http://secunia.com/advisories/51472Vendor Advisory
- http://www.securityfocus.com/bid/56819
- https://bugzilla.redhat.com/show_bug.cgi?id=882129
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80549
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.