Описание
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2016-7075
- https://github.com/kubernetes/kubernetes/issues/34517
- https://access.redhat.com/errata/RHSA-2016:2064
- https://access.redhat.com/security/cve/CVE-2016-7075
- https://bugzilla.redhat.com/show_bug.cgi?id=1384112
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7075
Связанные уязвимости
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
It was found that Kubernetes as used by Openshift Enterprise 3 did not ...