cbcvebase.
CVE-2019-10214
published 2019-11-25

CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container…

PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.60%
73.1th percentile
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

Affected

8 ranges
VendorProductVersion rangeFixed in
containersimage
debiangolang-github-containers-image< singularity-container 3.5.0+ds1-1 (sid)singularity-container 3.5.0+ds1-1 (sid)
debiansingularity-container< singularity-container 3.5.0+ds1-1 (sid)singularity-container 3.5.0+ds1-1 (sid)
github.comcontainers_image>= 0 < 3.0.03.0.0
github.comcontainers_image>= 0 < 2.0.2-0.20190802080134-634605d06e73+incompatible2.0.2-0.20190802080134-634605d06e73+incompatible
opensuseleap
redhatenterprise_linux
redhatopenshift_container_platform

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.