REDHAT-BUG-2278627: Medium severity Red Hat Satellite vulnerability

Published May 2, 2024
·
Updated

When running a remote execution job on a host, the ssh key of the host is not being checked. When the key changes, the Satellite connects it anyway because it uses "-o StrictHostKeyChecking=no". This can lead to MITM, DoS, leaking of whatever secrets the remote execution job contains, or whatever other issues may arise from the attacker being able to forge a ssh key. This does not directly allow unauthorized remote execution on the Satellite (although it can leak secrets leading to it)..

Affected Software

1 affected component
Red Hat Satellite

Event History

May 2, 2024
Data Sourced
via Red Hat·01:22 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2278627?

The severity of REDHAT-BUG-2278627 is medium with a CVSS score of 4.

2

How do I fix REDHAT-BUG-2278627?

To fix REDHAT-BUG-2278627, ensure that SSH key checking is enforced by avoiding the use of '-o StrictHostKeyChecking=no'.

3

What are the risks associated with REDHAT-BUG-2278627?

The risks associated with REDHAT-BUG-2278627 include potential man-in-the-middle attacks and exposure of sensitive information.

4

Which software is affected by REDHAT-BUG-2278627?

REDHAT-BUG-2278627 affects the Red Hat Satellite software.

5

When was REDHAT-BUG-2278627 published?

REDHAT-BUG-2278627 was published on May 2, 2024.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203