Описание
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
Отчет
This issue affects the versions of foreman as shipped with Red Hat Satellite 6 and OpenStack. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenStack Foreman | foreman | Affected | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installer | foreman | Affected | ||
| Red Hat Satellite 6.2 for RHEL 6 | candlepin | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | foreman | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | foreman-installer | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | foreman-proxy | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | foreman-selinux | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | gofer | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | katello | Fixed | RHBA-2016:1501 | 27.07.2016 |
| Red Hat Satellite 6.2 for RHEL 6 | katello-agent | Fixed | RHBA-2016:1501 | 27.07.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests ...
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
EPSS
4.3 Medium
CVSS2