REDHAT-BUG-2299429: Gunicorn vulnerability
An authentication bypass vulnerability exists in Foreman due to Pulpcore when deployed with Gunicorn versions earlier than 22.0. The issue arises from how Apache’s modproxy handles header as it fails to unset it properly due to restrictions on underscores in HTTP headers. This allow authentication through malformed header instead. This flaw affects all Katello/Satellite 6.10+ deployments using Pulpcore from version 4.0+ and could potentially allow unauthorized users to gain admin access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2299429?
The severity of REDHAT-BUG-2299429 is classified as a high-risk vulnerability due to the authentication bypass it causes.
How do I fix REDHAT-BUG-2299429?
To fix REDHAT-BUG-2299429, upgrade Gunicorn to version 22.0 or later, and ensure that your deployment of Pulpcore is updated accordingly.
Which versions of Gunicorn are affected by REDHAT-BUG-2299429?
Gunicorn versions earlier than 22.0 are affected by REDHAT-BUG-2299429.
What software is related to REDHAT-BUG-2299429?
REDHAT-BUG-2299429 impacts Gunicorn, Pulpcore, Red Hat Katello, and Red Hat Satellite versions specified.
Is there a workaround for REDHAT-BUG-2299429?
Currently, the best practice is to upgrade to the latest versions of the affected software rather than relying on a workaround.