CVE-2019-10150
Summary
| CVE | CVE-2019-10150 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-12 14:29:00 UTC |
| Updated | 2023-02-12 23:33:00 UTC |
| Description | It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Openshift Container Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1713433 – (CVE-2019-10150) CVE-2019-10150 atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository | CONFIRM | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| 1713433 – (CVE-2019-10150) CVE-2019-10150 atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository | MISC | bugzilla.redhat.com | |
| Red Hat Customer Portal | MISC | access.redhat.com | |
| Build Inputs - Builds | Developer Guide | OpenShift Container Platform 3.11 | MISC | docs.openshift.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.