GHSA-2qxw-7fmx-gqfm

Suggest an improvement
Source
https://github.com/advisories/GHSA-2qxw-7fmx-gqfm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-2qxw-7fmx-gqfm/GHSA-2qxw-7fmx-gqfm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2qxw-7fmx-gqfm
Aliases
  • CVE-2026-1531
Published
2026-02-02T06:30:53Z
Modified
2026-02-04T18:06:09.277104Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
foreman_kubevirt disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set
Details

A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information.

Database specific
{
    "severity": "HIGH",
    "cwe_ids": [
        "CWE-295"
    ],
    "github_reviewed_at": "2026-02-02T21:15:40Z",
    "github_reviewed": true,
    "nvd_published_at": "2026-02-02T06:16:20Z"
}
References

Affected packages

RubyGems / foreman_kubevirt

Package

Name
foreman_kubevirt
Purl
pkg:gem/foreman_kubevirt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.4.3

Affected versions

0.*
0.1.0
0.1.1
0.1.2
0.1.3
0.1.4
0.1.5
0.1.7
0.1.8
0.1.9
0.2.0
0.3.0
0.4.0
0.4.1
0.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-2qxw-7fmx-gqfm/GHSA-2qxw-7fmx-gqfm.json"