Red Hat Bugzilla – Bug 1059514
CVE-2014-0040 OpenStack openstack-heat-templates: use of HTTP to download signing keys/code
Last modified: 2016-04-26 17:07:34 EDT
There are a number of yum repositories that make connections via http (should be https). Also, signing keys can be downloaded over http instead of https. External reference: https://bugs.launchpad.net/heat-templates/+bug/1267635 https://github.com/openstack/heat-templates/ Acknowledgements: This issue was discovered by Grant Murphy of the Red Hat Product Security Team.
This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:0579 https://rhn.redhat.com/errata/RHSA-2014-0579.html