CVE-2017-2639
published 2018-07-27CVE-2017-2639: It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
1.14%
63.0th percentile
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | cloudforms | — | — |
| redhat | cloudforms_management_engine | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmm6-vqjm-5p45: It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicat
ghsa_unreviewed·2022-05-13
CVE-2017-2639 [HIGH] CWE-295 GHSA-gmm6-vqjm-5p45: It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicat
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
Red Hat
CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
vendor_redhat·2017-05-31·CVSS 6.5
CVE-2017-2639 [MEDIUM] CWE-295 CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
CloudForms: cloudforms fails to properly check certificates when communicating with RHEV and OpenShift and custom CA
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/98769http://www.securitytracker.com/id/1038599https://access.redhat.com/errata/RHSA-2017:1367https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2639http://www.securityfocus.com/bid/98769http://www.securitytracker.com/id/1038599https://access.redhat.com/errata/RHSA-2017:1367https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2639
2018-07-27
Published