6.5
CVSSv3

CVE-2022-1632

Published: 01/09/2022 Updated: 13/12/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an malicious user to exploit an invalid certificate, resulting in a loss of confidentiality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform 4.0

redhat ansible automation platform 2.0

fedoraproject fedora 34

fedoraproject fedora 35