Bug 1150879 (CVE-2014-3691) - CVE-2014-3691 foreman-proxy: failure to verify SSL certificates
Summary: CVE-2014-3691 foreman-proxy: failure to verify SSL certificates
Status: CLOSED ERRATA
Alias: CVE-2014-3691
Product: Security Response
Classification: Other
Component: vulnerability   
(Show other bugs)
Version: unspecified
Hardware: All Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=important,public=20141006,repo...
Keywords: Security
Depends On: 1152720 1152722 1152723
Blocks: 1150912
TreeView+ depends on / blocked
 
Reported: 2014-10-09 06:30 UTC by Murray McAllister
Modified: 2016-04-26 18:26 UTC (History)
22 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that foreman-proxy, when running in SSL-secured mode, did not correctly verify SSL client certificates. This could permit any client with access to the API to make requests and perform actions otherwise restricted.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-05-20 05:20:56 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0287 normal SHIPPED_LIVE Important: foreman-proxy security update 2015-03-04 02:09:25 UTC
Red Hat Product Errata RHSA-2015:0288 normal SHIPPED_LIVE Important: foreman-proxy security update 2015-03-04 01:58:44 UTC

Description Murray McAllister 2014-10-09 06:30:27 UTC
It was discovered that Foreman Smart Proxy failed to verify SSL certificates. As noted in the upstream bug, "This permits any client with access to the API to make requests and perform actions (permitting control of Puppet CA, DHCP, DNS etc.)".

A mitigation is available from the following:

https://groups.google.com/forum/#!topic/foreman-announce/jXC5ixybjqo

References:

http://projects.theforeman.org/issues/7822

Comment 5 errata-xmlrpc 2015-03-03 20:59:05 UTC
This issue has been addressed in the following products:

  OpenStack 4 for RHEL 6

Via RHSA-2015:0288 https://rhn.redhat.com/errata/RHSA-2015-0288.html

Comment 6 errata-xmlrpc 2015-03-03 21:09:34 UTC
This issue has been addressed in the following products:

  OpenStack Foreman for RHEL 6

Via RHSA-2015:0287 https://rhn.redhat.com/errata/RHSA-2015-0287.html

Comment 7 Kurt Seifried 2015-05-20 05:20:56 UTC
This issue has been addressed in the following products:

  Satellite 6

Via RHBA-2015:0054 https://access.redhat.com/errata/RHBA-2015:0054


Note You need to log in before you can comment on or make changes to this bug.