Skip to content

Commit 6ffc700

Browse files
jasnowpostmodern
authored andcommitted
GHSA SYNC: 2 brand new red hat advisories
1 parent 1cb1c83 commit 6ffc700

File tree

2 files changed

+55
-0
lines changed

2 files changed

+55
-0
lines changed
Lines changed: 29 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
---
2+
gem: fog-kubevirt
3+
cve: 2026-1530
4+
ghsa: m3hq-3qj8-c5fm
5+
url: https://access.redhat.com/security/cve/CVE-2026-1530
6+
title: fog-kubevirt allows remote attacker to perform MITM attack
7+
due to disabled certificate validation
8+
date: 2026-02-02
9+
description: |
10+
A flaw was found in fog-kubevirt. This vulnerability allows a remote
11+
attacker to perform a Man-in-the-Middle (MITM) attack due to disabled
12+
certificate validation. This enables the attacker to intercept and
13+
potentially alter sensitive communications between Satellite and
14+
OpenShift, resulting in information disclosure and data integrity
15+
compromise.
16+
cvss_v3: 8.1
17+
patched_versions:
18+
- ">= 1.5.1"
19+
related:
20+
url:
21+
- https://nvd.nist.gov/vuln/detail/CVE-2026-1530
22+
- https://github.com/fog/fog-kubevirt/releases/tag/v1.5.1
23+
- https://github.com/fog/fog-kubevirt/blob/8adb03e07972d6e19a7713ecf2a827aa2cfe4b9e/CHANGELOG.md?plain=1#L11
24+
- https://github.com/fog/fog-kubevirt/pull/168
25+
- https://github.com/fog/fog-kubevirt/commit/8371e9ded99f9ec3e74caf2f283836109763e450
26+
- https://github.com/fog/fog-kubevirt/commit/9603d79a239a0f68bedfc679cd1b65fbf6ec4753
27+
- https://access.redhat.com/security/cve/CVE-2026-1530
28+
- https://bugzilla.redhat.com/show_bug.cgi?id=2433784
29+
- https://github.com/advisories/GHSA-m3hq-3qj8-c5fm
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
---
2+
gem: foreman_kubevirt
3+
cve: 2026-1531
4+
ghsa: 2qxw-7fmx-gqfm
5+
url: https://access.redhat.com/security/cve/CVE-2026-1531
6+
title: foreman_kubevirt disables SSL verification if a Certificate
7+
Authority (CA) certificate is not explicitly set
8+
date: 2026-02-02
9+
description: |
10+
A flaw was found in foreman_kubevirt. When configuring the connection
11+
to OpenShift, the system disables SSL verification if a Certificate
12+
Authority (CA) certificate is not explicitly set. This insecure
13+
default allows a remote attacker, capable of intercepting network
14+
traffic between Satellite and OpenShift, to perform a Man-in-the-Middle
15+
(MITM) attack. Such an attack could lead to the disclosure or
16+
alteration of sensitive information.
17+
cvss_v3: 8.1
18+
patched_versions:
19+
- ">= 0.4.3"
20+
related:
21+
url:
22+
- https://nvd.nist.gov/vuln/detail/CVE-2026-1531
23+
- https://github.com/theforeman/foreman_kubevirt/commit/6c9973ee59c6fbec65f165eb9ea9dd4ebb6eeef1
24+
- https://access.redhat.com/security/cve/CVE-2026-1531
25+
- https://bugzilla.redhat.com/show_bug.cgi?id=2433786
26+
- https://github.com/advisories/GHSA-2qxw-7fmx-gqfm

0 commit comments

Comments
 (0)