Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To mitigate this issue, ensure that a Certificate Authority (CA) certificate is explicitly configured when setting up the connection to OpenShift in foreman_kubevirt. This will enable SSL verification and prevent Man-in-the-Middle attacks. Refer to the foreman_kubevirt documentation for specific instructions on configuring CA certificates. A restart or service reload may be required for the changes to take effect.
Mon, 02 Feb 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information. |
| Title | foreman-kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification | Foreman-kubevirt: foreman_kubevirt: man-in-the-middle due to insecure default ssl verification |
| First Time appeared |
Redhat
Redhat satellite |
|
| CPEs | cpe:/a:redhat:satellite:6 | |
| Vendors & Products |
Redhat
Redhat satellite |
|
| References |
|
Thu, 29 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | foreman-kubevirt: foreman_kubevirt: Man-in-the-Middle due to insecure default SSL verification | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-02-02T05:47:09.570Z
Reserved: 2026-01-28T12:52:40.355Z
Link: CVE-2026-1531
No data.
Status : Received
Published: 2026-02-02T06:16:20.790
Modified: 2026-02-02T06:16:20.790
Link: CVE-2026-1531
OpenCVE Enrichment
No data.