CVE-2012-5603

critical

Description

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to read consumer certificates or change arbitrary users' settings via unspecified vectors related to the "consumer UUID" of a system.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/80549

https://bugzilla.redhat.com/show_bug.cgi?id=882129

http://www.securityfocus.com/bid/56819

http://secunia.com/advisories/51472

http://rhn.redhat.com/errata/RHSA-2013-0544.html

http://rhn.redhat.com/errata/RHSA-2012-1543.html

http://osvdb.org/88142

http://osvdb.org/88140

Details

Source: Mitre, NVD

Published: 2013-01-04

Updated: 2017-08-29

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical