Security scan found an unsecure connection between RHN-Proxy to RHN-Satellite
Issue
There is a plain text authentication (unsecure connection) from RHN-Proxy to RHN-Satellite when accessing /rhn/account/UserPreferences.do
. Navigating to http://<RHN_PROXY>/rhn/account/UserPreferences.do
via the webui will result in not being redirected to HTTPS
. This also occurs with the internal call for /rhn/account/UserPreferences.do
between RHN-Proxy and RHN-Satellite.
Environment
- RHN-Proxy 5.4
- RHN-Proxy 5.5
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.