Описание
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
A flaw was found in Cockpit in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
Отчет
OpenShift Container Platform (OCP) 3 has transitioned to the maintenance phase of the product life cycle and receives only qualified Critical and Important impact security fixes. This issue has been rated as having a security impact of Moderate, and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat OpenShift Container Platform 3 Life Cycle Policy - https://access.redhat.com/support/policy/updates/openshift_noncurrent
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | cockpit | Out of support scope | ||
Red Hat Enterprise Linux 9 | cockpit | Not affected | ||
Red Hat OpenShift Container Platform 3.11 | cockpit | Out of support scope | ||
Red Hat Virtualization 4 | cockpit | Not affected | ||
Red Hat Enterprise Linux 8 | cockpit | Fixed | RHSA-2022:2008 | 10.05.2022 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
A flaw was found in Cockpit in versions prior to 260 in the way it han ...
EPSS
7.5 High
CVSS3