RHSA-2018:2733: Critical: rubygem-smart_proxy_dynflow security update
The rubygem provided by rubygem-smartproxydynflow is a plugin into Foreman's Smart Proxy for running Dynflow actions on the Smart Proxy.Security Fix(es): smartproxydynflow: Authentication bypass in Foreman remote execution feature (CVE-2018-14643) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.This issue was discovered by Ivan Necas (Red Hat).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:2733?
The severity of RHSA-2018:2733 is classified as critical due to an authentication bypass vulnerability.
How do I fix RHSA-2018:2733?
To fix RHSA-2018:2733, you should update the smart_proxy_dynflow gem to the latest version that includes the security fix.
What components are affected by RHSA-2018:2733?
RHSA-2018:2733 affects the smart_proxy_dynflow plugin used in Foreman's Smart Proxy.
What vulnerability is addressed in RHSA-2018:2733?
RHSA-2018:2733 addresses an authentication bypass vulnerability identified as CVE-2018-14643.
When was RHSA-2018:2733 released?
RHSA-2018:2733 was released on December 4, 2018.