PT-2013-6046 · Red Hat · Candlepin+1

Adrian Likins

+1

·

Published

2013-12-23

·

Updated

2023-02-13

·

CVE-2013-6439

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Subscription Asset Manager versions 1.0 through 1.3
Description The issue concerns a weak authentication scheme used by Candlepin in Red Hat Subscription Asset Manager when the configuration file does not specify a scheme. This has an unspecified impact and attack vectors.
Recommendations For versions 1.0 through 1.3, consider specifying a secure authentication scheme in the configuration file to mitigate the risk of exploitation. As a temporary workaround, review and strengthen the authentication configuration to minimize potential vulnerabilities.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2013-6439

Affected Products

Candlepin
Red Hat Subscription Asset Manager