CVE-2014-8164

CRITICAL

Red Hat CloudForms 5.x - Certificate Validation Bypass via Insecure OpenSSL Verify Mode

Title source: llm
STIX 2.1

Description

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x.

References (1)

Core 1
Core References
Issue Tracking, Mitigation, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1151208

Scores

CVSS v3 9.1
EPSS 0.0051
EPSS Percentile 39.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-295
Status published
Products (1)
redhat/cloudforms_management_engine 5.0
Published Jul 06, 2022
Tracked Since Feb 18, 2026