CVE-2014-0104: Medium severity ClusterLabs fence-agents vulnerability
In fence-agents before 4.0.17 does not verify remote SSL certificates in the fenceciscoucs.py script which can potentially allow for man-in-the-middle attackers to spoof SSL servers via arbitrary SSL certificates.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-0104?
CVE-2014-0104 is a vulnerability in fence-agents before version 4.0.17 that allows for potential man-in-the-middle attacks by not verifying remote SSL certificates.
How does CVE-2014-0104 affect fence-agents?
CVE-2014-0104 affects fence-agents before version 4.0.17 by not verifying remote SSL certificates, which could be exploited by man-in-the-middle attackers to spoof SSL servers.
What is the severity of CVE-2014-0104?
CVE-2014-0104 has a severity rating of medium with a score of 5.9.
Which software versions are affected by CVE-2014-0104?
CVE-2014-0104 affects fence-agents versions up to and excluding 4.0.17.
How can I mitigate CVE-2014-0104?
To mitigate CVE-2014-0104, update fence-agents to version 4.0.17 or higher.