Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remote attackers to bypass intended authentication and execute arbitrary API requests via a request without a certificate.
Weaknesses in this category are related to the design and implementation of data confidentiality and integrity. Frequently these deal with the use of encoding techniques, encryption libraries, and hashing algorithms. The weaknesses in this category could lead to a degradation of the quality data if they are not addressed.
Link | Tags |
---|---|
https://github.com/theforeman/smart-proxy/pull/217 | issue tracking patch |
http://projects.theforeman.org/issues/7822 | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0287.html | third party advisory vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0288.html | third party advisory vendor advisory |
https://groups.google.com/forum/#%21topic/foreman-announce/jXC5ixybjqo |