Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0188

Опубликовано: 23 апр. 2014
Источник: redhat
CVSS2: 7.5

Описание

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

Меры по смягчению последствий

add this in the host httpd conf global config, e.g. at the end of /etc/httpd/conf.d/000002_openshift_origin_broker_proxy.conf: RequestHeader unset X-Remote-User

Дополнительная информация

Статус:

Critical
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1090120OpenShift: openshift-origin-broker plugin allows impersonation

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

github
больше 3 лет назад

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

7.5 High

CVSS2