PT-2019-11638 · Red Hat+4 · Skopeo+10

Marian Rehak

+1

·

Published

2019-09-10

·

Updated

2024-06-15

·

CVE-2019-10214

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions: containers/image library used by Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 CRI-O in OpenShift Container Platform
Description: The issue concerns the containers/image library, which does not enforce TLS connections to the container registry authorization service. This allows an attacker to launch a Man-in-the-Middle (MiTM) attack, potentially stealing login credentials or bearer tokens. The HTTP client used to connect to the container registry authorization service explicitly disables TLS verification, making it vulnerable to such attacks.
Recommendations: For Red Hat Enterprise Linux version 8, update the containers/image library to a version that enforces TLS connections. For OpenShift Container Platform, update CRI-O to a version that enforces TLS connections. As a temporary workaround, consider restricting access to the container registry authorization service to minimize the risk of exploitation.

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:3403
ALSA-2019:3494
CESA-2019_3403
CESA-2019_3494
CVE-2019-10214
GHSA-85P9-J7C9-V4GR
GO-2021-0081
OPENSUSE-SU-2019:2137-1
OPENSUSE-SU-2019:2138-1
OPENSUSE-SU-2019:2143-1
OPENSUSE-SU-2019:2159-1
OPENSUSE-SU-2019_2137-1
OPENSUSE-SU-2019_2138-1
OPENSUSE-SU-2019_2143-1
OPENSUSE-SU-2019_2159-1
OPENSUSE-SU-2020:0377-1
OPENSUSE-SU-2020:0554-1
OPENSUSE-SU-2020:2106-1
OPENSUSE-SU-2020_0377-1
OPENSUSE-SU-2020_0554-1
OPENSUSE-SU-2020_2106-1
OPENSUSE-SU-2021:0310-1
OPENSUSE-SU-2021_0310-1
OPENSUSE-SU-2022:0770-1
OPENSUSE-SU-2022_0770-1
OPENSUSE-SU-2024:10666-1
OPENSUSE-SU-2024:10699-1
OPENSUSE-SU-2024:11177-1
OPENSUSE-SU-2024:11385-1
RHSA-2019:2817
RHSA-2019:2825
RHSA-2019:2989
RHSA-2019:3403
RHSA-2019:3494
RHSA-2019:3812
RHSA-2019_3403
RHSA-2019_3494
RLSA-2019:3403
RLSA-2019:3494
SUSE-SU-2019:2340-1
SUSE-SU-2019:2341-1
SUSE-SU-2019:2346-1
SUSE-SU-2019_2340-1
SUSE-SU-2019_2341-1
SUSE-SU-2019_2346-1
SUSE-SU-2020:0712-1
SUSE-SU-2020:3423-1
SUSE-SU-2020_0712-1
SUSE-SU-2022:0770-1

Affected Products

Almalinux
Buildah
Cri-O
Centos
Openshift Container Platform
Podman
Red Hat
Rocky Linux
Skopeo
Suse
Containers/Image Library