Back

HIGH

OpenShift: openshift-origin-broker plugin allows impersonation

Published Apr 24, 2014

Description

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

Affected products

Remediation

Red Hat mitigation

add this in the host httpd conf global config, e.g. at the end of /etc/httpd/conf.d/000002_openshift_origin_broker_proxy.conf: RequestHeader unset X-Remote-User

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 24, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date Apr 23, 2014