CVE-2017-7513: Red Hat Satellite
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate.
Affected products
- Red Hat Satellite: version 5.0 only; version 5.1.1 only; version 5.2 only; version 5.3 only; version 5.4 only; version 5.4.1 only; …
Published 2018-08-22. Last modified 2026-06-17.