REDHAT-BUG-2278627: Medium severity Red Hat Satellite vulnerability
When running a remote execution job on a host, the ssh key of the host is not being checked. When the key changes, the Satellite connects it anyway because it uses "-o StrictHostKeyChecking=no". This can lead to MITM, DoS, leaking of whatever secrets the remote execution job contains, or whatever other issues may arise from the attacker being able to forge a ssh key. This does not directly allow unauthorized remote execution on the Satellite (although it can leak secrets leading to it)..
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2278627?
The severity of REDHAT-BUG-2278627 is medium with a CVSS score of 4.
How do I fix REDHAT-BUG-2278627?
To fix REDHAT-BUG-2278627, ensure that SSH key checking is enforced by avoiding the use of '-o StrictHostKeyChecking=no'.
What are the risks associated with REDHAT-BUG-2278627?
The risks associated with REDHAT-BUG-2278627 include potential man-in-the-middle attacks and exposure of sensitive information.
Which software is affected by REDHAT-BUG-2278627?
REDHAT-BUG-2278627 affects the Red Hat Satellite software.
When was REDHAT-BUG-2278627 published?
REDHAT-BUG-2278627 was published on May 2, 2024.