Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-0759

Опубликовано: 25 мар. 2022
Источник: nvd
CVSS3: 8.1
CVSS2: 6.8
EPSS Низкий

Описание

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:kubeclient:*:*:*:*:*:ruby:*:*
Версия до 4.9.3 (исключая)

EPSS

Процентиль: 34%
0.00137
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.3
redhat
почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.1
debian
почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not includin ...

CVSS3: 8.1
github
почти 4 года назад

Improper Certificate Validation in kubeclient

CVSS3: 8.3
fstec
почти 4 года назад

Уязвимость реализации класса Kubeclient::Configе клиента REST API Kubernetes kubeclient, позволяющая нарушителю выполнить атаку типа «человек посередине»

EPSS

Процентиль: 34%
0.00137
Низкий

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-295
CWE-295