{"api_version":"1","generated_at":"2026-07-23T09:31:59+00:00","cve":"CVE-2019-10150","urls":{"html":"https://cve.report/CVE-2019-10150","api":"https://cve.report/api/cve/CVE-2019-10150.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10150","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10150"},"summary":{"title":"CVE-2019-10150","description":"It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-06-12 14:29:00","updated_at":"2023-02-12 23:33:00"},"problem_types":["CWE-287"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150","refsource":"CONFIRM","tags":["Issue Tracking","Vendor Advisory"],"title":"1713433 – (CVE-2019-10150) CVE-2019-10150 atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:3811","name":"RHSA-2019:3811","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:3007","name":"RHSA-2019:3007","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:3143","name":"RHSA-2019:3143","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:2989","name":"RHSA-2019:2989","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1713433","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1713433","refsource":"MISC","tags":[],"title":"1713433 – (CVE-2019-10150) CVE-2019-10150 atomic-openshift: OpenShift builds don't verify SSH Host Keys for the git repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2019-10150","name":"https://access.redhat.com/security/cve/CVE-2019-10150","refsource":"MISC","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication","name":"https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication","refsource":"MISC","tags":["Vendor Advisory"],"title":"Build Inputs - Builds | Developer Guide | OpenShift Container Platform 3.11","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10150","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10150","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10150","vulnerable":"1","versionEndIncluding":"4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift_container_platform","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2019-10150","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-287","cweId":"CWE-287"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"redhat","product":{"product_data":[{"product_name":"atomic-openshift","version":{"version_data":[{"version_affected":"=","version_value":"3.6.x - 4.0.0"}]}}]}}]}},"references":{"reference_data":[{"url":"https://access.redhat.com/errata/RHSA-2019:2989","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:2989"},{"url":"https://access.redhat.com/errata/RHSA-2019:3007","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:3007"},{"url":"https://access.redhat.com/errata/RHSA-2019:3143","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:3143"},{"url":"https://access.redhat.com/errata/RHSA-2019:3811","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2019:3811"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150"},{"url":"https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication","refsource":"MISC","name":"https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication"}]},"impact":{"cvss":[{"attackComplexity":"HIGH","attackVector":"ADJACENT_NETWORK","availabilityImpact":"LOW","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L","version":"3.0"}]}},"nvd":{"publishedDate":"2019-06-12 14:29:00","lastModifiedDate":"2023-02-12 23:33:00","problem_types":["CWE-287"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6","versionEndIncluding":"4.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10150","Ordinal":"148367","Title":"CVE-2019-10150","CVE":"CVE-2019-10150","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10150","Ordinal":"1","NoteData":"It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10150","Ordinal":"2","NoteData":"2019-06-12","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10150","Ordinal":"3","NoteData":"2019-11-07","Type":"Other","Title":"Modified"}]}}}