CVE-2017-2639: High severity red hat cloudforms vulnerability
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2639?
CVE-2017-2639 is a vulnerability found in CloudForms that allows an attacker to spoof Red Hat Virtualization (RHEV) or OpenShift systems and potentially harvest sensitive information.
What is the severity of CVE-2017-2639?
The severity of CVE-2017-2639 is rated as high with a CVSS score of 7.5.
How does CVE-2017-2639 affect Redhat Cloudforms?
CVE-2017-2639 affects Redhat Cloudforms versions 4.5 and Redhat Cloudforms Management Engine version 5.8.
How can an attacker exploit CVE-2017-2639?
An attacker can exploit CVE-2017-2639 by spoofing RHEV or OpenShift systems and potentially gain access to sensitive information.
Is there a fix available for CVE-2017-2639?
Yes, a fix for CVE-2017-2639 is available. Please refer to the official Red Hat advisory for more information.