Lucene search

K
redhatRedHatRHSA-2014:0423
HistoryApr 23, 2014 - 12:00 a.m.

(RHSA-2014:0423) Critical: openshift-origin-broker security update

2014-04-2300:00:00
access.redhat.com
14

0.006 Low

EPSS

Percentile

79.1%

The openshift-origin-broker package provides the OpenShift Broker service
that manages all user logins, DNS name resolution, application states, and
general orchestration of the applications.

The rubygem-openshift-origin-auth-remote-user package provides the remote
user authentication plug-in.

A flaw was found in the way openshift-origin-broker handled authentication
requests via the remote user authentication plug-in. A remote attacker able
to submit a request to openshift-origin-broker could set the X-Remote-User
header, and send the request to a passthrough trigger, resulting in a
bypass of the authentication checks to gain access to any OpenShift user
account on the system. (CVE-2014-0188)

All users of Red Hat OpenShift Enterprise 2.0.5 are advised to upgrade to
these updated packages, which contain a backported patch to correct this
issue. After installing the updated packages, restart the httpd daemon for
this update to take effect.

0.006 Low

EPSS

Percentile

79.1%