First published: Fri Jul 27 2018(Updated: )
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Cloudforms | =4.5 | |
Redhat Cloudforms Management Engine | =5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2639 is a vulnerability found in CloudForms that allows an attacker to spoof Red Hat Virtualization (RHEV) or OpenShift systems and potentially harvest sensitive information.
The severity of CVE-2017-2639 is rated as high with a CVSS score of 7.5.
CVE-2017-2639 affects Redhat Cloudforms versions 4.5 and Redhat Cloudforms Management Engine version 5.8.
An attacker can exploit CVE-2017-2639 by spoofing RHEV or OpenShift systems and potentially gain access to sensitive information.
Yes, a fix for CVE-2017-2639 is available. Please refer to the official Red Hat advisory for more information.