Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1328345 | issue tracking patch |
http://www.openwall.com/lists/oss-security/2016/04/18/5 | mailing list third party advisory patch |
https://bugzilla.redhat.com/show_bug.cgi?id=1003326 | issue tracking patch |
https://github.com/pulp/pulp/pull/627 | issue tracking third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/05/20/1 | third party advisory mailing list |
http://www.openwall.com/lists/oss-security/2016/04/18/11 | third party advisory mailing list |