Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3818

Опубликовано: 05 фев. 2019
Источник: nvd
CVSS3: 3.7
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:kube-rbac-proxy_project:kube-rbac-proxy:*:*:*:*:*:*:*:*
Версия до 0.4.1 (исключая)
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00075
Низкий

3.7 Low

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-327
CWE-327

Связанные уязвимости

CVSS3: 3.7
redhat
около 7 лет назад

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.

CVSS3: 7.5
github
больше 3 лет назад

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.

EPSS

Процентиль: 23%
0.00075
Низкий

3.7 Low

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-327
CWE-327