Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3hq-3qj8-c5fm

Опубликовано: 02 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation

A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise.

Пакеты

Наименование

fog-kubevirt

rubygems
Затронутые версииВерсия исправления

< 1.5.1

1.5.1

EPSS

Процентиль: 4%
0.00019
Низкий

8.1 High

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 8.1
nvd
5 дней назад

A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise.

EPSS

Процентиль: 4%
0.00019
Низкий

8.1 High

CVSS3

Дефекты

CWE-295