CVE-2012-0059
published 2014-02-05CVE-2012-0059: A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user…
PriorityP423medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
1.64%
73.6th percentile
A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_proxy | — | — |
| redhat | satellite | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2012-0059: A flaw was found in Spacewalk-backend
vendor_redhat·2014-02-05·CVSS 4.9
CVE-2012-0059 [MEDIUM] CWE-209 CVE-2012-0059: A flaw was found in Spacewalk-backend
A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
A flaw was found in Spacewalk-backend. This information disclosure vulnerability occurs when a system registration XML-RPC call fails, causing cleartext user passwords to be included in error messages. Remote administrators can exploit this by reading server logs and emails, leading to the unauthorized disclosure of user passwords.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product S
GHSA
GHSA-gqj9-6pwj-7952: Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5
ghsa_unreviewed·2022-05-04
CVE-2012-0059 [MEDIUM] CWE-209 GHSA-gqj9-6pwj-7952: Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5
Spacewalk-backend in Red Hat Network (RHN) Satellite and Proxy 5.4 includes cleartext user passwords in an error message when a system registration XML-RPC call fails, which allows remote administrators to obtain the password by reading (1) the server log and (2) an email.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
bugzilla·2012-11-19·CVSS 6.5
CVE-2012-5471 [MEDIUM] CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also
Bugzilla
CVE-2012-0059 Satellite, Spacewalk: RHN user password disclosure upon failed system registration
bugzilla·2012-01-18·CVSS 4.9
CVE-2012-0059 [MEDIUM] CVE-2012-0059 Satellite, Spacewalk: RHN user password disclosure upon failed system registration
CVE-2012-0059 Satellite, Spacewalk: RHN user password disclosure upon failed system registration
A password disclosure flaw was found in the way Red Hat Network (RHN) Satellite Server, RHN Proxy Server and Spacewalk performed new system registration in the case of XMLRPC call failure. If a RHN Satellite, Proxy or Spacewalk user submitted a XMLRPC system registration call (together with their credentials) and processing of this request resulted in a failure, RHN Satellite, Proxy or Spacewalk administrator could use this deficiency to obtain plaintext form of a password for particular RHN Satellite, Proxy or Spacewalk user.
References:
[1] https://bugzilla.redhat.com/show_bug.cgi?id=749890
Spacewalk upstream patch:
[2] http://git.fedorahosted.org/git/?p=spacewalk.git;a=commitdiff;h=76d006
2014-02-05
Published