|
|
| |
|
| |
vdsm: insecure node image
| Package(s): | vdsm |
CVE #(s): | CVE-2012-5518
|
| Created: | March 12, 2013 |
Updated: | March 13, 2013 |
| Description: |
From the Red Hat bugzilla:
When new node image is being created, vdsm.rpm is added to the node image and self-signed key (and certificate) is created. This key/cert allows vdsm to start and serve requests from anyone who has a matching key/cert which could be anybody holding the node image.
Upstream fix:
http://gerrit.ovirt.org/#/c/8368/ |
| Alerts: |
|
( Log in to post comments)
|
|
|