Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ccwq-5269-25p2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

EPSS

Процентиль: 53%
0.00304
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.9
redhat
больше 6 лет назад

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

CVSS3: 5.9
nvd
больше 6 лет назад

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость корпоративной платформы Red Hat OpenShift Container Platform, позволяющая нарушителю перенаправить сетевой трафик

EPSS

Процентиль: 53%
0.00304
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-287