CVE-2012-5603: Medium severity red hat cloudforms vulnerability
Lukas Zapletal of Red Hat reports:
Regular user (somebody with username and password) and a consumer UUID of any system can download the consumer certificate and consume content or modify data without permission to do that.
Other sources
proxiescontroller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the "consumer UUID" of a system.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5603?
CVE-2012-5603 has a moderate severity rating due to unauthorized access to consumer certificates.
How do I fix CVE-2012-5603?
To fix CVE-2012-5603, update Red Hat CloudForms to version 1.1 or higher.
Who is affected by CVE-2012-5603?
Users of Red Hat CloudForms versions up to 1.0 are affected by CVE-2012-5603.
What type of vulnerability is CVE-2012-5603?
CVE-2012-5603 is an unauthorized access vulnerability that allows users to modify data without permission.
What is the consequence of CVE-2012-5603?
The consequence of CVE-2012-5603 is potential unauthorized modification of data and consumption of protected content.