5.9
CVSSv3

CVE-2019-10214

Published: 25/11/2019 Updated: 28/10/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

buildah project buildah -

libpod project libpod -

redhat openshift container platform 4.1

skopeo project skopeo -

redhat enterprise linux 8.0

opensuse leap 15.1

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 310 atomic-openshift kube-apiserver security update Type/Severity Security Advisory: Moderate Topic An update for atomic-openshift kube-apiserver is now available for Red Hat OpenShift Container Platform 310Red Hat Product Security has rated this update as ...
Synopsis Important: container-tools:rhel8 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Im ...
Synopsis Moderate: OpenShift Container Platform 39 cri-o security update Type/Severity Security Advisory: Moderate Topic An update for cri-o is now available for Red Hat OpenShift Container Platform 39Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnera ...
Synopsis Moderate: OpenShift Container Platform 311 security update Type/Severity Security Advisory: Moderate Topic An update for cri-o is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
Synopsis Important: container-tools:10 security and bug fix update Type/Severity Security Advisory: Important Topic An update for the container-tools:10 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common ...
Synopsis Moderate: OpenShift Container Platform 4117 cri-o security update Type/Severity Security Advisory: Moderate Topic An update for cri-o is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vuln ...
Synopsis Moderate: OpenShift Container Platform 4120 openshift-enterprise-builder-container security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-builder-container is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated ...
Impact: Moderate Public Date: 2019-09-09 CWE: CWE-522 Bugzilla: 1732508: CVE-2019-10214 containers/imag ...