It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
2018-07-27T13:29:00.287
2024-11-21T03:23:53.240
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | cloudforms | 4.5 | Yes |
| Application | redhat | cloudforms_management_engine | 5.8 | Yes |