Vulnerabilites related to ipa - ipa
CVE-2012-5631 (GCVE-0-2012-5631)
Vulnerability from cvelistv5
Published
2019-11-25 14:08
Modified
2024-08-06 21:14
Severity ?
CWE
  • client does not properly check server identity before sending cookies that contain credentials
Summary
ipa 3.0 does not properly check server identity before sending credential containing cookies
Impacted products
Vendor Product Version
ipa ipa Version: Fixed in freeipa 3.0.2
Version: freeipa 3.1.0
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-06T21:14:15.936Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5631"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://access.redhat.com/security/cve/cve-2012-5631"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "http://www.securityfocus.com/bid/56919"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80784"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "ipa",
          "vendor": "ipa",
          "versions": [
            {
              "status": "affected",
              "version": "Fixed in freeipa 3.0.2"
            },
            {
              "status": "affected",
              "version": "freeipa 3.1.0"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "ipa 3.0 does not properly check server identity before sending credential containing cookies"
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "client does not properly check server identity before sending cookies that contain credentials",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2019-11-25T14:08:28",
        "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "shortName": "redhat"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5631"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://access.redhat.com/security/cve/cve-2012-5631"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "http://www.securityfocus.com/bid/56919"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80784"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "secalert@redhat.com",
          "ID": "CVE-2012-5631",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "ipa",
                      "version": {
                        "version_data": [
                          {
                            "version_value": "Fixed in freeipa 3.0.2"
                          },
                          {
                            "version_value": "freeipa 3.1.0"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "ipa"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "ipa 3.0 does not properly check server identity before sending credential containing cookies"
            }
          ]
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "client does not properly check server identity before sending cookies that contain credentials"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5631",
              "refsource": "MISC",
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5631"
            },
            {
              "name": "https://access.redhat.com/security/cve/cve-2012-5631",
              "refsource": "MISC",
              "url": "https://access.redhat.com/security/cve/cve-2012-5631"
            },
            {
              "name": "http://www.securityfocus.com/bid/56919",
              "refsource": "MISC",
              "url": "http://www.securityfocus.com/bid/56919"
            },
            {
              "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80784",
              "refsource": "MISC",
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80784"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
    "assignerShortName": "redhat",
    "cveId": "CVE-2012-5631",
    "datePublished": "2019-11-25T14:08:28",
    "dateReserved": "2012-10-24T00:00:00",
    "dateUpdated": "2024-08-06T21:14:15.936Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}