REDHAT-BUG-2447319: High severity Samba Samba vulnerability
Samba: group policy certificate enrollment uses http:// without validation
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure Samba group policy certificate enrollment to use https:// endpoints and enable validation of the enrollment URL and the server certificate. Do not use http:// without validation for certificate enrollment.
Samba (Group Policy certificate enrollment) enrollment transport and URL validation = use https and enable validation - Compensating control
If you cannot immediately reconfigure enrollment to use HTTPS and validation, restrict access to the certificate enrollment HTTP endpoints via firewall/ACLs to trusted management networks and hosts only, and monitor enrollment activity until the secure configuration can be applied.
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2447319?
The severity of REDHAT-BUG-2447319 is high, rated at 7.
What does REDHAT-BUG-2447319 describe?
REDHAT-BUG-2447319 describes a vulnerability in Samba where group policy certificate enrollment uses HTTP without proper validation.
How do I fix REDHAT-BUG-2447319?
To fix REDHAT-BUG-2447319, ensure that Samba is updated to a version that addresses this certificate enrollment issue.
What risk level is associated with REDHAT-BUG-2447319?
REDHAT-BUG-2447319 has a risk level of 33.
Which software is affected by REDHAT-BUG-2447319?
The affected software in REDHAT-BUG-2447319 is Samba.