Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3818

Опубликовано: 25 янв. 2019
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.

The kube-rbac-proxy container, as used in Red Hat OpenShift Container Platform, does not honor TLS configurations allowing for the use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption of the data stream.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4/ose-kube-rbac-proxyNot affected
Red Hat OpenShift Container Platform 3.11openshift3/apb-baseFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/apb-toolsFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/automation-broker-apbFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-attacherFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-driver-registrarFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-livenessprobeFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/csi-provisionerFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/grafanaFixedRHBA-2019:032720.02.2019
Red Hat OpenShift Container Platform 3.11openshift3/jenkins-slave-base-rhel7FixedRHBA-2019:032720.02.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-327
https://bugzilla.redhat.com/show_bug.cgi?id=1668961kube-rbac-proxy: Improper application of config allows for insecure ciphers and TLS 1.0

EPSS

Процентиль: 23%
0.00075
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 7 лет назад

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.

CVSS3: 7.5
github
больше 3 лет назад

The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.

EPSS

Процентиль: 23%
0.00075
Низкий

3.7 Low

CVSS3

Уязвимость CVE-2019-3818