Lucene search

K
osvGoogleOSV:CVE-2022-1632
HistorySep 01, 2022 - 9:15 p.m.

CVE-2022-1632

2022-09-0121:15:08
Google
osv.dev
4
openshift
certificate validation
attack
route
destinationcacertificate
service tls
confidentiality
software

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.

6.7 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

Related for OSV:CVE-2022-1632