REDHAT-BUG-959041: High severity red hat cloudforms vulnerability
Ruby on Rails uses a HMAC for verifying the integrity of signed cookies. To prevent session hash tampering, a digest is calculated from the session with a server-side secret and inserted into the end of the cookie.
It was found that CloudForms Management Engine (CFME) is using a statically defined secret, which is common across all deployments. A remote attacker could use this statically defined secret to perform a session tampering attack.
External references:
http://blog.phusion.nl/2013/01/04/securing-the-rails-session-secret/ http://blog.mhartl.com/2008/08/15/a-security-issue-with-rails-secret-session-keys/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-959041?
The severity of REDHAT-BUG-959041 is classified as high due to the potential for session hash tampering.
How do I fix REDHAT-BUG-959041?
To fix REDHAT-BUG-959041, ensure that your CloudForms Management Engine is updated to the latest version with the security patch applied.
What version of software is affected by REDHAT-BUG-959041?
REDHAT-BUG-959041 affects Red Hat CloudForms 3.0.4 Management Engine.
What type of vulnerability is described in REDHAT-BUG-959041?
REDHAT-BUG-959041 describes a vulnerability related to session hash tampering through statically defined secrets in Ruby on Rails cookies.
Who is the vendor for REDHAT-BUG-959041?
The vendor for REDHAT-BUG-959041 is Red Hat.