REDHAT-BUG-1042677: High severity red hat subscription asset manager vulnerability
Devan Goodwin <dgoodwin> reports:
We have identified a fairly serious security issue in previous, or upgraded versions of Subscription Asset Manager (SAM).
The issue was caused by an extremely insecure authentication mode in the candlepin project, which was mistakenly enabled by default if no setting was specified in the config file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1042677?
The severity of REDHAT-BUG-1042677 is considered fairly serious due to the insecure authentication mode.
How do I fix REDHAT-BUG-1042677?
To fix REDHAT-BUG-1042677, you should disable the insecure authentication mode in Subscription Asset Manager.
Which versions are affected by REDHAT-BUG-1042677?
All previous or upgraded versions of Red Hat Subscription Asset Manager and Red Hat Candlepin may be affected by REDHAT-BUG-1042677.
What causes the vulnerability REDHAT-BUG-1042677?
The vulnerability REDHAT-BUG-1042677 is caused by an insecure authentication mode that was mistakenly enabled by default.
Who reported the vulnerability REDHAT-BUG-1042677?
The vulnerability REDHAT-BUG-1042677 was reported by Devan Goodwin.