First published: Thu Jan 30 2014(Updated: )
Grant Murphy of the Red Hat Product Security team reports: There are a number of yum repositories configured with sslverify=false which removes SSL protections. External reference: <a href="https://bugs.launchpad.net/heat-templates/+bug/1267635">https://bugs.launchpad.net/heat-templates/+bug/1267635</a> <a href="https://github.com/openstack/heat-templates/">https://github.com/openstack/heat-templates/</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack for IBM Power | =4.0 | |
=4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0041 has been classified as a moderate severity vulnerability due to the potential exposure of SSL protections.
To mitigate CVE-2014-0041, configure your yum repositories to enable SSL verification by setting sslverify=true.
CVE-2014-0041 specifically affects Red Hat OpenStack version 4.0.
The primary risk associated with CVE-2014-0041 is the potential for man-in-the-middle attacks due to disabled SSL verification.
Yes, Red Hat has issued a security advisory that includes patches to address CVE-2014-0041.