CVE-2019-10214

Aliases:GHSA-85p9-j7c9-v4grGO-2021-0081
Modified
Published: 25 Nov 2019, 10:41
Last modified:04 Aug 2024, 22:17

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.4 MEDIUM
v3.0 (cve.org)
EPSS Score
0.41% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Nov 2019, 10:41
Published
Vulnerability first disclosed
04 Aug 2024, 22:17
Last Modified
Vulnerability information updated

Description

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS Metrics

  • v3.1MEDIUMScore: 5.9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v3.1MEDIUMScore: 6.4CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
  • v3.0MEDIUMScore: 6.4CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS Trends

Current EPSS score: 0.41% Percentile: 62%

Techniques & Countermeasures

  • CWE-522Insufficiently Protected Credentials

    The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Systems

  • buildah_projectbuildah

    na

  • github.com/containersimage

    < 3.0.0 | < 2.0.2-0.20190802080134-634605d06e73+incompatible

  • libpod_projectlibpod

    na

  • opensuseleap

    15.1

  • redhatenterprise_linux

    8.0

  • redhatopenshift_container_platform

    4.1

  • skopeo_projectskopeo

    na

References (11)