CVE-2012-3503
Last modified
CVE-2012-3503 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.. EPSS estimates a 3.00% chance of exploitation in the next 30 days.
Description
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default secret_token.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Theforeman | Katello | <= 1.0 |
| Redhat | Enterprise Linux Server | 6.0 |
References
- http://rhn.redhat.com/errata/RHSA-2012-1186.htmlBroken Link, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1187.htmlThird Party Advisory
- http://secunia.com/advisories/50344Broken Link
- http://www.securityfocus.com/bid/55140Broken Link, Third Party Advisory, VDB Entry
- https://github.com/Katello/katello/pull/499Issue Tracking
- http://rhn.redhat.com/errata/RHSA-2012-1186.htmlBroken Link, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1187.htmlThird Party Advisory
- http://secunia.com/advisories/50344Broken Link
- http://www.securityfocus.com/bid/55140Broken Link, Third Party Advisory, VDB Entry
- https://github.com/Katello/katello/pull/499Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-3503?
How severe is CVE-2012-3503?
How do I fix CVE-2012-3503?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-3497(1) TMEMC_SAVE_GET_CLIENT_WEIGHT, (2) TMEMC_SAVE_GET_CLIENT_…
- CVE-2012-3498PHYSDEVOP_map_pirq in Xen 4.1 and 4.2 and Citrix XenServer 6…
- CVE-2012-3499Multiple cross-site scripting (XSS) vulnerabilities in the A…
- CVE-2012-3500scripts/annotate-output.sh in devscripts before 2.12.2, as u…
- CVE-2012-3501The squidclamav_check_preview_handler function in squidclama…
- CVE-2012-3502The proxy functionality in (1) mod_proxy_ajp.c in the mod_pr…
- CVE-2012-3504The nssconfigFound function in genkey.pl in crypto-utils 2.4…
- CVE-2012-3505Tinyproxy 1.8.3 and earlier allows remote attackers to cause…
- CVE-2012-3506Unspecified vulnerability in the Apache Open For Business Pr…
- CVE-2012-3507Cross-site scripting (XSS) vulnerability in program/steps/ma…
- CVE-2012-3508Cross-site scripting (XSS) vulnerability in program/lib/wash…
- CVE-2012-3509Multiple integer overflows in the (1) _objalloc_alloc functi…
Are you affected by CVE-2012-3503?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
