vdsm: insecure node image
Package(s): | vdsm | CVE #(s): | CVE-2012-5518 | ||||
Created: | March 12, 2013 | Updated: | March 13, 2013 | ||||
Description: | From the Red Hat bugzilla:
When new node image is being created, vdsm.rpm is added to the node image and self-signed key (and certificate) is created. This key/cert allows vdsm to start and serve requests from anyone who has a matching key/cert which could be anybody holding the node image.
Upstream fix: | ||||||
Alerts: |
|