PT-2019-11638 · Red Hat+4 · Skopeo+10

Marian Rehak

+1

·

Publicado

2019-09-10

·

Atualizado

2024-06-15

·

CVE-2019-10214

CVSS v3.1

7.0

Alta

VetorAV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: containers/image library used by Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 CRI-O in OpenShift Container Platform
Description: The issue concerns the containers/image library, which does not enforce TLS connections to the container registry authorization service. This allows an attacker to launch a Man-in-the-Middle (MiTM) attack, potentially stealing login credentials or bearer tokens. The HTTP client used to connect to the container registry authorization service explicitly disables TLS verification, making it vulnerable to such attacks.
Recommendations: For Red Hat Enterprise Linux version 8, update the containers/image library to a version that enforces TLS connections. For OpenShift Container Platform, update CRI-O to a version that enforces TLS connections. As a temporary workaround, consider restricting access to the container registry authorization service to minimize the risk of exploitation.

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2019:3403
ALSA-2019:3494
CESA-2019_3403
CESA-2019_3494
CVE-2019-10214
GHSA-85P9-J7C9-V4GR
GO-2021-0081
OPENSUSE-SU-2019:2137-1
OPENSUSE-SU-2019:2138-1
OPENSUSE-SU-2019:2143-1
OPENSUSE-SU-2019:2159-1
OPENSUSE-SU-2019_2137-1
OPENSUSE-SU-2019_2138-1
OPENSUSE-SU-2019_2143-1
OPENSUSE-SU-2019_2159-1
OPENSUSE-SU-2020:0377-1
OPENSUSE-SU-2020:0554-1
OPENSUSE-SU-2020:2106-1
OPENSUSE-SU-2020_0377-1
OPENSUSE-SU-2020_0554-1
OPENSUSE-SU-2020_2106-1
OPENSUSE-SU-2021:0310-1
OPENSUSE-SU-2021_0310-1
OPENSUSE-SU-2022:0770-1
OPENSUSE-SU-2022_0770-1
OPENSUSE-SU-2024:10666-1
OPENSUSE-SU-2024:10699-1
OPENSUSE-SU-2024:11177-1
OPENSUSE-SU-2024:11385-1
RHSA-2019:2817
RHSA-2019:2825
RHSA-2019:2989
RHSA-2019:3403
RHSA-2019:3494
RHSA-2019:3812
RHSA-2019_3403
RHSA-2019_3494
RLSA-2019:3403
RLSA-2019:3494
SUSE-SU-2019:2340-1
SUSE-SU-2019:2341-1
SUSE-SU-2019:2346-1
SUSE-SU-2019_2340-1
SUSE-SU-2019_2341-1
SUSE-SU-2019_2346-1
SUSE-SU-2020:0712-1
SUSE-SU-2020:3423-1
SUSE-SU-2020_0712-1
SUSE-SU-2022:0770-1

Produtos afetados

Almalinux
Buildah
Cri-O
Centos
Openshift Container Platform
Podman
Red Hat
Rocky Linux
Skopeo
Suse
Containers/Image Library