First published: Thu Oct 09 2014(Updated: )
A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat CloudForms Management Engine | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8164 has been classified with a high severity since it allows for certificate verification bypass.
To fix CVE-2014-8164, ensure that the configuration for http.verify_mode is set to OpenSSL::SSL::VERIFY_PEER instead of OpenSSL::SSL::VERIFY_NONE.
CVE-2014-8164 specifically affects Red Hat CloudForms Management Engine version 5.0.
CVE-2014-8164 involves an insecure configuration for certificate verification that could lead to security vulnerabilities in CloudForms.
Yes, CVE-2014-8164 is a publicly known vulnerability reported in Red Hat CloudForms.