CVE-2014-0188
published 2014-04-24CVE-2014-0188: The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user…
PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.67%
74.1th percentile
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | <= 1.2.7 | — |
| redhat | openshift | 2.0 – 2.0.5 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Red Hat openshift up to 2.0.5 improper authentication (Bug 1090120 / SBV-44467)
vuldb·2026-05-12·CVSS 7.5
CVE-2014-0188 [HIGH] Red Hat openshift up to 2.0.5 improper authentication (Bug 1090120 / SBV-44467)
A vulnerability was found in Red Hat openshift up to 2.0.5 and classified as problematic. The impacted element is an unknown function. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2014-0188. The attack can be launched remotely. No exploit exists.
GHSA
GHSA-p2j4-wp52-g89q: The openshift-origin-broker in Red Hat OpenShift Enterprise 2
ghsa_unreviewed·2022-05-14
CVE-2014-0188 [HIGH] CWE-287 GHSA-p2j4-wp52-g89q: The openshift-origin-broker in Red Hat OpenShift Enterprise 2
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.
Red Hat
OpenShift: openshift-origin-broker plugin allows impersonation
vendor_redhat·2014-04-23·CVSS 7.5
CVE-2014-0188 [HIGH] CWE-287 OpenShift: openshift-origin-broker plugin allows impersonation
OpenShift: openshift-origin-broker plugin allows impersonation
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.
Mitigation: add this in the host httpd conf global config, e.g. at the
end of /etc/httpd/conf.d/000002_openshift_origin_broker_proxy.conf:
RequestHeader unset X-Remote-User
No detection rules found.
No public exploits indexed.
2014-04-24
Published