Spoofing Vulnerability in CloudForms Affecting Red Hat Virtualization and OpenShift
CVE-2017-2639

6.5MEDIUM

Key Information:

Vendor

[unknown]

Vendor
CVE Published:
27 July 2018

What is CVE-2017-2639?

A security concern exists in CloudForms that arises from the lack of validation of server hostnames against the domain names in certificates when utilizing a custom Certificate Authority (CA). This oversight enables potential attackers to impersonate Red Hat Virtualization (RHEV) and OpenShift environments, thereby allowing unauthorized access and the possibility of sensitive data exposure from CloudForms. Proper hostname verification is crucial to prevent such vulnerabilities.

Affected Version(s)

CloudForms

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.