Описание
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat OpenShift Container Platform 4 | podman | Affected | ||
Red Hat OpenShift Container Platform 4 | skopeo | Affected | ||
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2019:3403 | 05.11.2019 |
Red Hat Enterprise Linux 8 | container-tools | Fixed | RHSA-2019:3494 | 05.11.2019 |
Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Fixed | RHSA-2019:2989 | 14.10.2019 |
Red Hat OpenShift Container Platform 3.10 | cri-o | Fixed | RHSA-2019:2989 | 14.10.2019 |
Red Hat OpenShift Container Platform 3.11 | cri-o | Fixed | RHSA-2019:2817 | 23.09.2019 |
Red Hat OpenShift Container Platform 3.9 | cri-o | Fixed | RHSA-2019:3812 | 07.11.2019 |
Red Hat OpenShift Container Platform 4.1 | cri-o | Fixed | RHSA-2019:2825 | 25.09.2019 |
Red Hat OpenShift Container Platform 4.1 | openshift4/ose-docker-builder | Fixed | RHSA-2019:3007 | 16.10.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS3
Связанные уязвимости
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
The containers/image library used by the container tools Podman, Build ...
EPSS
6.4 Medium
CVSS3