ZeroHour

CVE-2017-2639

CVSS 3.0
7.5 high
EPSS
1%p65
Published
()
Modified
Description

It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.

Vendors
redhat
Products
cloudforms, cloudforms management engine
Weakness
CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.