First published: Thu Jan 30 2014(Updated: )
OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, uses an HTTP connection to download (1) packages and (2) signing keys from Yum repositories, which allows man-in-the-middle attackers to prevent updates via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack for IBM Power | =4.0 | |
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0040 is considered a medium severity vulnerability due to its potential impact on system updates.
To mitigate CVE-2014-0040, it is recommended to switch to secure HTTPS connections when downloading packages and signing keys.
CVE-2014-0040 can be exploited by man-in-the-middle attackers who can intercept HTTP connections to Yum repositories.
CVE-2014-0040 affects Red Hat Enterprise Linux OpenStack Platform 4.0 and its heat-templates.
CVE-2014-0040 was disclosed in 2014 and is part of the vulnerabilities affecting OpenStack Heat.