VDB
Sign up
HIGH8.1

GHSA-m3hq-3qj8-c5fm

fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation

Quick fix

GHSA-m3hq-3qj8-c5fm — fog-kubevirt: upgrade to the fixed version with the command below.

bundle update fog-kubevirt

Details

A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/fog-kubevirt
Introduced in: 0Fixed in: 1.5.1
Fixbundle update fog-kubevirt

References