Bug 1150879 - (CVE-2014-3691) CVE-2014-3691 foreman-proxy: failure to verify SSL certificates
CVE-2014-3691 foreman-proxy: failure to verify SSL certificates
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20141006,repo...
: Security
Depends On: 1152720 1152722 1152723
Blocks: 1150912
  Show dependency treegraph
 
Reported: 2014-10-09 02:30 EDT by Murray McAllister
Modified: 2016-04-26 14:26 EDT (History)
22 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was discovered that foreman-proxy, when running in SSL-secured mode, did not correctly verify SSL client certificates. This could permit any client with access to the API to make requests and perform actions otherwise restricted.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-05-20 01:20:56 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Murray McAllister 2014-10-09 02:30:27 EDT
It was discovered that Foreman Smart Proxy failed to verify SSL certificates. As noted in the upstream bug, "This permits any client with access to the API to make requests and perform actions (permitting control of Puppet CA, DHCP, DNS etc.)".

A mitigation is available from the following:

https://groups.google.com/forum/#!topic/foreman-announce/jXC5ixybjqo

References:

http://projects.theforeman.org/issues/7822
Comment 5 errata-xmlrpc 2015-03-03 15:59:05 EST
This issue has been addressed in the following products:

  OpenStack 4 for RHEL 6

Via RHSA-2015:0288 https://rhn.redhat.com/errata/RHSA-2015-0288.html
Comment 6 errata-xmlrpc 2015-03-03 16:09:34 EST
This issue has been addressed in the following products:

  OpenStack Foreman for RHEL 6

Via RHSA-2015:0287 https://rhn.redhat.com/errata/RHSA-2015-0287.html
Comment 7 Kurt Seifried 2015-05-20 01:20:56 EDT
This issue has been addressed in the following products:

  Satellite 6

Via RHBA-2015:0054 https://access.redhat.com/errata/RHBA-2015:0054

Note You need to log in before you can comment on or make changes to this bug.