CVE-2019-10214Insufficiently Protected Credentials in Containers Image

Severity
5.9MEDIUMNVD
EPSS
0.5%
top 35.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 25
Latest updateFeb 15

Description

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

CVEListV5containers/image3.0.0
NVDopensuse/leap15.1

Also affects: Openshift Container Platform 4.1, Enterprise Linux 8.0

Patches

🔴Vulnerability Details

5
GHSA
containers/image library Insufficiently Protects Credentials2022-02-15
OSV
containers/image library Insufficiently Protects Credentials2022-02-15
OSV
Insufficiently Protected Credentials in github.com/containers/image2021-04-14
OSV
CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Cont2019-11-25
CVEList
CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Cont2019-11-25

📋Vendor Advisories

2
Red Hat
containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure2019-09-09
Debian
CVE-2019-10214: golang-github-containers-image - The containers/image library used by the container tools Podman, Buildah, and Sk...2019

💬Community

1
Bugzilla
CVE-2019-10214 containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure2019-07-23
CVE-2019-10214 — Insufficiently Protected Credentials | cvebase