CVE-2013-2049: High severity red hat cloudforms management engine vulnerability
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secrettoken.rb secret.
Other sources
Ruby on Rails uses a HMAC for verifying the integrity of signed cookies. To prevent session hash tampering, a digest is calculated from the session with a server-side secret and inserted into the end of the cookie.
It was found that CloudForms Management Engine (CFME) is using a statically defined secret, which is common across all deployments. A remote attacker could use this statically defined secret to perform a session tampering attack.
External references:
http://blog.phusion.nl/2013/01/04/securing-the-rails-session-secret/ http://blog.mhartl.com/2008/08/15/a-security-issue-with-rails-secret-session-keys/
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is CVE-2013-2049?
CVE-2013-2049 is a vulnerability in Red Hat CloudForms 2 Management Engine (CFME) that allows remote attackers to conduct session tampering attacks.
How does CVE-2013-2049 affect Red Hat CloudForms Management Engine?
CVE-2013-2049 affects Red Hat CloudForms Management Engine version 2.0.
What is the severity of CVE-2013-2049?
CVE-2013-2049 has a severity rating of 7.5, which is considered high.
How can remote attackers exploit CVE-2013-2049?
Remote attackers can exploit CVE-2013-2049 by leveraging the use of a static secret_token.rb secret to conduct session tampering attacks.
Is there a fix for CVE-2013-2049?
Yes, there is a fix available for CVE-2013-2049. It is recommended to update to a patched version of Red Hat CloudForms Management Engine.