Lucene search

K
cvelistRedhatCVELIST:CVE-2022-1632
HistorySep 01, 2022 - 12:00 a.m.

CVE-2022-1632

2022-09-0100:00:00
CWE-295
redhat
www.cve.org
cve-2022-1632
openshift
re-encrypt route
destinationcacertificate
service tls certificate
confidentiality

0.001 Low

EPSS

Percentile

28.6%

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "Openshift",
    "versions": [
      {
        "version": "4.8.17",
        "status": "affected"
      }
    ]
  }
]

0.001 Low

EPSS

Percentile

28.6%

Related for CVELIST:CVE-2022-1632