CVE-2012-5604: Medium severity red hat cloudforms vulnerability
Og Maciel of Red Hat reports:
After configuring my system to use ActiveDirectory as the authentication method, I was able to login via the web ui without having to provide a password when using Windows ADS as the LDAP authentication backend.
Other sources
The ldapfluff gem for Ruby, as used in Red Hat CloudForms 1.1, when using Active Directory for authentication, allows remote attackers to bypass authentication via unspecified vectors.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5604?
CVE-2012-5604 is considered a high severity vulnerability due to the potential for unauthorized access without password authentication.
How do I fix CVE-2012-5604?
To fix CVE-2012-5604, upgrade to a version of Red Hat CloudForms that has patched this vulnerability.
What systems are affected by CVE-2012-5604?
CVE-2012-5604 affects Red Hat CloudForms version 1.1 when configured with ActiveDirectory as the authentication method.
What type of vulnerability is CVE-2012-5604?
CVE-2012-5604 is categorized as an authentication bypass vulnerability.
Is CVE-2012-5604 related to ActiveDirectory configuration?
Yes, CVE-2012-5604 is specifically related to the improper handling of authentication when using ActiveDirectory as the LDAP backend.