REDHAT-BUG-885130: Medium severity red hat dnf plugin subscription manager vulnerability
A security flaw was found in the way rhn-migrate-classic-to-rhsm tool of subscription-manager, a suite of tools and libraries for subscription and repository management, performed migration of system profiles, registered with Red Hat Network Classic to Customer Portal Subscription Management (certificate of Red Hat Network Classic server was not verified for validity). A rogue server could use this flaw to conduct man-in-the-middle (MiTM) attacks, possibly leading to their ability to obtain user credentials, that would be used for authentication of that particular user at Red Hat Network Classic server before the system profile(s) migration.
This issue was found by Florian Weimer of Red Hat Product Security Team.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-885130?
The severity of REDHAT-BUG-885130 is categorized as moderate.
How do I fix REDHAT-BUG-885130?
To fix REDHAT-BUG-885130, apply the latest updates for the subscription-manager tool from Red Hat.
What software is affected by REDHAT-BUG-885130?
REDHAT-BUG-885130 affects the Red Hat subscription-manager tool.
What is the main issue described in REDHAT-BUG-885130?
The main issue in REDHAT-BUG-885130 is a flaw in the rhn-migrate-classic-to-rhsm tool during system profile migration.
Is there a workaround for REDHAT-BUG-885130?
Currently, there are no official workarounds for REDHAT-BUG-885130 other than applying available patches.