Spoofing Vulnerability in CloudForms Affecting Red Hat Virtualization and OpenShift
CVE-2017-2639
6.5MEDIUM
What is CVE-2017-2639?
A security concern exists in CloudForms that arises from the lack of validation of server hostnames against the domain names in certificates when utilizing a custom Certificate Authority (CA). This oversight enables potential attackers to impersonate Red Hat Virtualization (RHEV) and OpenShift environments, thereby allowing unauthorized access and the possibility of sensitive data exposure from CloudForms. Proper hostname verification is crucial to prevent such vulnerabilities.
Affected Version(s)
CloudForms