Логотип exploitDog
bind:CVE-2022-0759
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-0759

Количество 6

Количество 6

ubuntu логотип

CVE-2022-0759

почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-0759

почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2022-0759

почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2022-0759

почти 4 года назад

A flaw was found in all versions of kubeclient up to (but not includin ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-69p3-xp37-f692

почти 4 года назад

Improper Certificate Validation in kubeclient

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2022-01721

почти 4 года назад

Уязвимость реализации класса Kubeclient::Configе клиента REST API Kubernetes kubeclient, позволяющая нарушителю выполнить атаку типа «человек посередине»

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.1
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.3
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to verify certs, kubeclient ends up accepting any certificate (it wrongly returns VERIFY_NONE). Ruby applications that leverage kubeclient to parse kubeconfig files are susceptible to Man-in-the-middle attacks (MITM).

CVSS3: 8.1
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not includin ...

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-69p3-xp37-f692

Improper Certificate Validation in kubeclient

CVSS3: 8.1
0%
Низкий
почти 4 года назад
fstec логотип
BDU:2022-01721

Уязвимость реализации класса Kubeclient::Configе клиента REST API Kubernetes kubeclient, позволяющая нарушителю выполнить атаку типа «человек посередине»

CVSS3: 8.3
0%
Низкий
почти 4 года назад

Уязвимостей на страницу