Security Advisory

CVE-2024-7923

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-09-04 13:41:48
Last updated 2025-11-11 16:12:18
Assigner redhat
State PUBLISHED

Description

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore configuration. This issue arises from Apaches mod_proxy not properly unsetting headers because of restrictions on underscores in HTTP headers, allowing authentication through a malformed header. This flaw impacts all active Satellite deployments (6.13, 6.14 and 6.15) which are using Pulpcore version 3.0+ and could potentially enable unauthorized users to gain administrative access.