CVE-2019-3818 — Use of a Broken or Risky Cryptographic Algorithm in Project Kube-rbac-proxy
Severity
7.5HIGHNVD
EPSS
0.1%
top 77.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 13
Description
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages1 packages
Also affects: Openshift Container Platform 3.11
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Red Hat
▶
💬Community
1Bugzilla▶
CVE-2019-3818 kube-rbac-proxy: Improper application of config allows for insecure ciphers and TLS 1.0↗2019-01-24