CVE-2014-3691

Redhat Openstack < 1.5.3 - Cryptographic Issue

Title source: rule
STIX 2.1

Description

Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.

References (5)

Core 5
Core References
Issue Tracking, Patch x_refsource_confirm
https://github.com/theforeman/smart-proxy/pull/217
Vendor Advisory x_refsource_confirm
http://projects.theforeman.org/issues/7822
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0287.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0288.html

Scores

EPSS 0.0171
EPSS Percentile 74.9%

Details

CWE
CWE-310
Status published
Products (5)
redhat/openstack 4.0
redhat/openstack 5.0
theforeman/foreman 1.6.0
theforeman/foreman 1.6.1
theforeman/foreman < 1.5.3
Published Mar 09, 2015
Tracked Since Feb 18, 2026