Red Hat Bugzilla – Bug 1059515
CVE-2014-0041 OpenStack openstack-heat-templates: use of HTTPS url and sslverify=false
Last modified: 2016-04-26 11:42:10 EDT
Grant Murphy of the Red Hat Product Security team reports: There are a number of yum repositories configured with sslverify=false which removes SSL protections. External reference: https://bugs.launchpad.net/heat-templates/+bug/1267635 https://github.com/openstack/heat-templates/
Acknowledgements: This issue was discovered by Grant Murphy of the Red Hat Product Security Team.
This issue has been addressed in following products: OpenStack 4 for RHEL 6 Via RHSA-2014:0579 https://rhn.redhat.com/errata/RHSA-2014-0579.html