Bug 1150879 (CVE-2014-3691)

Summary: CVE-2014-3691 foreman-proxy: failure to verify SSL certificates
Product: [Other] Security Response Reporter: Murray McAllister <mmcallis>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, bkearney, chrisw, cpelland, dallan, dcleal, gkotton, gmollett, katello-bugs, lhh, lpeer, markmc, mburns, mmccune, rbryant, rhos-maint, sclewis, tjay, yeylon
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
It was discovered that foreman-proxy, when running in SSL-secured mode, did not correctly verify SSL client certificates. This could permit any client with access to the API to make requests and perform actions otherwise restricted.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-05-20 05:20:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1152720, 1152722, 1152723    
Bug Blocks: 1150912    

Description Murray McAllister 2014-10-09 06:30:27 UTC
It was discovered that Foreman Smart Proxy failed to verify SSL certificates. As noted in the upstream bug, "This permits any client with access to the API to make requests and perform actions (permitting control of Puppet CA, DHCP, DNS etc.)".

A mitigation is available from the following:

https://groups.google.com/forum/#!topic/foreman-announce/jXC5ixybjqo

References:

http://projects.theforeman.org/issues/7822

Comment 5 errata-xmlrpc 2015-03-03 20:59:05 UTC
This issue has been addressed in the following products:

  OpenStack 4 for RHEL 6

Via RHSA-2015:0288 https://rhn.redhat.com/errata/RHSA-2015-0288.html

Comment 6 errata-xmlrpc 2015-03-03 21:09:34 UTC
This issue has been addressed in the following products:

  OpenStack Foreman for RHEL 6

Via RHSA-2015:0287 https://rhn.redhat.com/errata/RHSA-2015-0287.html

Comment 7 Kurt Seifried 2015-05-20 05:20:56 UTC
This issue has been addressed in the following products:

  Satellite 6

Via RHBA-2015:0054 https://access.redhat.com/errata/RHBA-2015:0054