Actions
Bug #37786
closedCVE-2024-7012: Authentication bypass in Foreman
Fixed in Releases:
Found in Releases:
Description
An authentication bypass vulnerability has been identified in Foreman when deployed by the Foreman Installer with External Authentication.
This issue arises from the way Apache is configured to do certificate authentication and pass this information to the Puma backend, without unsetting all headers coming from a possibly malicious client.
Actions