Release date:
Updated on:
Affected Systems:
RedHat OpenShift Origin 2.0.5
RedHat OpenShift Origin 1.2.7
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67037
CVE (CAN) ID: CVE-2014-0188
Red Hat OpenShift Origin is a cloud computing platform and service.
In Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier versions, openshift-origin-broker does not properly process authentication requests from the remote user authentication plug-in, this allows Remote attackers to bypass authentication and simulate arbitrary users by transferring the X-Remote-User header in the trigger request.
<* Source: vendor
Link: https://bugzilla.redhat.com/show_bug.cgi? Id = 1090120
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.redhat.com/apps/support/errata/index.html
OpenShift Origin details: click here