Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10150

Опубликовано: 12 июн. 2019
Источник: nvd
CVSS3: 5.9
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*
Версия от 3.6 (включая) до 4.1 (включая)

EPSS

Процентиль: 53%
0.00304
Низкий

5.9 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 5.9
redhat
больше 6 лет назад

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

CVSS3: 5.9
github
больше 3 лет назад

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость корпоративной платформы Red Hat OpenShift Container Platform, позволяющая нарушителю перенаправить сетевой трафик

EPSS

Процентиль: 53%
0.00304
Низкий

5.9 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287
CWE-287