PT-2022-7802 · Red Hat · Red Hat Cloudforms
Published
2022-07-06
·
Updated
2022-07-14
·
CVE-2014-8164
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat CloudForms version 5.x
Description
The issue is related to an insecure configuration for certificate verification, where the setting
http.verify mode is set to OpenSSL::SSL::VERIFY NONE. This may lead to a verification bypass.Recommendations
For Red Hat CloudForms version 5.x, change the
http.verify mode setting from OpenSSL::SSL::VERIFY NONE to a more secure verification mode to prevent verification bypass.Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Cloudforms