CVE-2019-10214
published 2019-11-25CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
1.60%
73.1th percentile
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| containers | image | — | — |
| debian | golang-github-containers-image | < singularity-container 3.5.0+ds1-1 (sid) | singularity-container 3.5.0+ds1-1 (sid) |
| debian | singularity-container | < singularity-container 3.5.0+ds1-1 (sid) | singularity-container 3.5.0+ds1-1 (sid) |
| github.com | containers_image | >= 0 < 3.0.0 | 3.0.0 |
| github.com | containers_image | >= 0 < 2.0.2-0.20190802080134-634605d06e73+incompatible | 2.0.2-0.20190802080134-634605d06e73+incompatible |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.4MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
containers/image library Insufficiently Protects Credentials
ghsa·2022-02-15
CVE-2019-10214 [MEDIUM] CWE-522 containers/image library Insufficiently Protects Credentials
containers/image library Insufficiently Protects Credentials
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
OSV
containers/image library Insufficiently Protects Credentials
osv·2022-02-15
CVE-2019-10214 [MEDIUM] containers/image library Insufficiently Protects Credentials
containers/image library Insufficiently Protects Credentials
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
OSV
Insufficiently Protected Credentials in github.com/containers/image
osv·2021-04-14
CVE-2019-10214 Insufficiently Protected Credentials in github.com/containers/image
Insufficiently Protected Credentials in github.com/containers/image
The HTTP client used to connect to the container registry authorization service explicitly disables TLS verification, allowing an attacker that is able to MITM the connection to steal credentials.
OSV
CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Cont
osv·2019-11-25·CVSS 5.9
CVE-2019-10214 [MEDIUM] CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Cont
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Red Hat
containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure
vendor_redhat·2019-09-09·CVSS 5.9
CVE-2019-10214 [MEDIUM] CWE-522 containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure
containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM atta
Debian
CVE-2019-10214: golang-github-containers-image - The containers/image library used by the container tools Podman, Buildah, and Sk...
vendor_debian·2019·CVSS 5.9
CVE-2019-10214 [MEDIUM] CVE-2019-10214: golang-github-containers-image - The containers/image library used by the container tools Podman, Buildah, and Sk...
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10214http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10214
2019-11-25
Published