OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets gpgcheck to 0 for certain templates, which disables GPG signature checking on downloaded packages and allows man-in-the-middle attackers to install arbitrary packages via unspecified vectors.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2014-06-02T15:00:00
Updated: 2024-08-06T08:58:26.613Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0042
Vulnrichment
No data.
NVD
Status : Modified
Published: 2014-06-02T15:55:11.683
Modified: 2024-11-21T02:01:14.167
Link: CVE-2014-0042
Redhat