Lucene search

K
cveRedhatCVE-2019-10214
HistoryNov 25, 2019 - 11:15 a.m.

CVE-2019-10214

2019-11-2511:15:11
CWE-522
redhat
web.nvd.nist.gov
246
cve-2019-10214
containers/image
podman
buildah
skopeo
red hat enterprise linux
cri-o
openshift container platform
tls
mitm
authorization service
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

39.7%

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

Affected configurations

Nvd
Vulners
Node
buildah_projectbuildahMatch-
OR
libpod_projectlibpodMatch-
OR
redhatopenshift_container_platformMatch4.1
OR
skopeo_projectskopeoMatch-
OR
redhatenterprise_linuxMatch8.0
Node
opensuseleapMatch15.1
VendorProductVersionCPE
buildah_projectbuildah-cpe:2.3:a:buildah_project:buildah:-:*:*:*:*:*:*:*
libpod_projectlibpod-cpe:2.3:a:libpod_project:libpod:-:*:*:*:*:*:*:*
redhatopenshift_container_platform4.1cpe:2.3:a:redhat:openshift_container_platform:4.1:*:*:*:*:*:*:*
skopeo_projectskopeo-cpe:2.3:a:skopeo_project:skopeo:-:*:*:*:*:*:*:*
redhatenterprise_linux8.0cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
opensuseleap15.1cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "containers/image",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "3.0.0"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

39.7%