cbcvebase.
CVE-2020-25688
published 2020-11-23

CVE-2020-25688: A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the…

PriorityP415low3.5CVSS 3.1
AVAACLPRLUINSUCLINAN
EPSS
0.25%
16.2th percentile
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.

Affected

1 ranges
VendorProductVersion rangeFixed in
redhatadvanced_cluster_management_for_kubernetes< 2.0.52.0.5

CVSS provenance

nvdv3.13.5LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.