CVE-2016-7075
published 2018-09-10CVE-2016-7075: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker…
PriorityP347high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
1.57%
72.6th percentile
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | < kubernetes 1.5.5+dfsg-1 (bookworm) | kubernetes 1.5.5+dfsg-1 (bookworm) |
| kubernetes | kubernetes | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| kubernetes | kubernetes | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| kubernetes | kubernetes | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| kubernetes | kubernetes | >= 0 < 1.5.5+dfsg-1 | 1.5.5+dfsg-1 |
| red_hat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7w66-j2r2-vm3p: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X
ghsa_unreviewed·2022-05-13
CVE-2016-7075 [HIGH] CWE-295 GHSA-7w66-j2r2-vm3p: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
OSV
CVE-2016-7075: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X
osv·2018-09-10·CVSS 8.1
CVE-2016-7075 [HIGH] CVE-2016-7075: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Red Hat
3: API server does not validate client-provided intermediate certificates correctly
vendor_redhat·2016-10-10·CVSS 7.5
CVE-2016-7075 [HIGH] CWE-295 3: API server does not validate client-provided intermediate certificates correctly
3: API server does not validate client-provided intermediate certificates correctly
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
It was found that Kubernetes did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Debian
CVE-2016-7075: kubernetes - It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly...
vendor_debian·2016·CVSS 7.5
CVE-2016-7075 [HIGH] CVE-2016-7075: kubernetes - It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly...
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Scope: local
bookworm: resolved (fixed in 1.5.5+dfsg-1)
bullseye: resolved (fixed in 1.5.5+dfsg-1)
forky: resolved (fixed in 1.5.5+dfsg-1)
sid: resolved (fixed in 1.5.5+dfsg-1)
trixie: resolved (fixed in 1.5.5+dfsg-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2016:2064https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7075https://github.com/kubernetes/kubernetes/issues/34517https://access.redhat.com/errata/RHSA-2016:2064https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7075https://github.com/kubernetes/kubernetes/issues/34517
2018-09-10
Published