Spoofing Vulnerability in CloudForms Affecting Red Hat Virtualization and OpenShift
CVE-2017-2639

6.5MEDIUM

Key Information:

Vendor

[unknown]

Vendor
CVE Published:
27 July 2018

What is CVE-2017-2639?

A security concern exists in CloudForms that arises from the lack of validation of server hostnames against the domain names in certificates when utilizing a custom Certificate Authority (CA). This oversight enables potential attackers to impersonate Red Hat Virtualization (RHEV) and OpenShift environments, thereby allowing unauthorized access and the possibility of sensitive data exposure from CloudForms. Proper hostname verification is crucial to prevent such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CloudForms

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.