REDHAT-BUG-2305718: Gunicorn vulnerability
An authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn versions prior to 22.0, due to the puppet-foreman configuration. This issue arises from Apache's modproxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 4.0+ and could potentially enable unauthorized users to gain administrative access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2305718?
The severity of REDHAT-BUG-2305718 is critical due to the authentication bypass vulnerability.
How do I fix REDHAT-BUG-2305718?
To fix REDHAT-BUG-2305718, upgrade Gunicorn to version 22.0 or later and ensure proper configuration of puppet-foreman.
Which versions of Gunicorn are affected by REDHAT-BUG-2305718?
Gunicorn versions prior to 22.0 are affected by REDHAT-BUG-2305718.
Which other software is impacted by REDHAT-BUG-2305718 besides Gunicorn?
Foreman, Satellite (versions 6.13 to 6.16), and Pulpcore (version 4.0 and above) are also impacted by REDHAT-BUG-2305718.
What causes the vulnerability in REDHAT-BUG-2305718?
The vulnerability in REDHAT-BUG-2305718 is caused by Apache's mod_proxy not properly unsetting headers due to restrictions on underscores in HTTP headers.