It was discovered that Foreman Smart Proxy failed to verify SSL certificates. As noted in the upstream bug, "This permits any client with access to the API to make requests and perform actions (permitting control of Puppet CA, DHCP, DNS etc.)". A mitigation is available from the following: https://groups.google.com/forum/#!topic/foreman-announce/jXC5ixybjqo References: http://projects.theforeman.org/issues/7822
This issue has been addressed in the following products: OpenStack 4 for RHEL 6 Via RHSA-2015:0288 https://rhn.redhat.com/errata/RHSA-2015-0288.html
This issue has been addressed in the following products: OpenStack Foreman for RHEL 6 Via RHSA-2015:0287 https://rhn.redhat.com/errata/RHSA-2015-0287.html
This issue has been addressed in the following products: Satellite 6 Via RHBA-2015:0054 https://access.redhat.com/errata/RHBA-2015:0054