Bug 1429632 (CVE-2017-2639)

Summary: CVE-2017-2639 CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: cpelland, dajohnso, gblomqui, gmccullo, gtanzill, hhudgeon, istein, jfrey, jhardy, jprause, jrafanie, juan.hernandez, obarenbo, roliveri, security-response-team, simaishi
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 03:08:45 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1429633, 1429634    
Bug Blocks: 1429637    

Description Kurt Seifried 2017-03-06 17:43:55 UTC
Cloudforms fails to properly validate SSL/TLS certificates when communicating with RHEV and OpenShift and using a custom CA.

Comment 3 errata-xmlrpc 2017-05-31 14:39:01 UTC
This issue has been addressed in the following products:

  CloudForms Management Engine 5.8

Via RHSA-2017:1367 https://access.redhat.com/errata/RHSA-2017:1367