Bug 1311145 (CVE-2016-2102)

Summary: CVE-2016-2102 openstack-tripleo-image-elements: HAProxy statistics are non-authenticated over network
Product: [Other] Security Response Reporter: Adam Mariš <amaris>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: abaron, aortega, apevec, ayoung, bnemec, bperkins, chrisw, dallan, gkotton, jjoyce, jschluet, jslagle, kbasil, lhh, lpeer, markmc, mburns, rbryant, sclewis, security-response-team, slinaber, tdecacqu, tsuter
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-05-03 06:06:30 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1311383, 1320602, 1332373, 1332374    
Bug Blocks: 1302938    

Description Adam Mariš 2016-02-23 13:45:48 UTC
It was found that HAProxy statistics are non-authenticated over network.

elements/haproxy/os-apply-config/etc/haproxy/haproxy.cfg:

listen haproxy.stats :{{#stats.port}}{{stats.port}}{{/stats.port}}{{^stats.port}}1993{{/stats.port}}

Comment 3 Tim Suter 2016-05-03 06:03:03 UTC
Created openstack-tripleo-image-elements tracking bugs for this issue:

Affects: fedora-all [bug 1332374]

Comment 4 Tim Suter 2016-05-03 06:06:30 UTC
issue solved in RHOSP current release - trackers filed for opensource projects