CVE-2017-2639
27.07.2018, 13:29
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | cloudforms | 4.5 |
redhat | cloudforms_management_engine | 5.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References