CVE-2020-25688
published 2020-11-23CVE-2020-25688: A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the…
PriorityP415low3.5CVSS 3.1
AVAACLPRLUINSUCLINAN
EPSS
0.25%
16.2th percentile
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | < 2.0.5 | 2.0.5 |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xm77-mpc2-5mxx: A flaw was found in rhacm versions before 2
ghsa_unreviewed·2022-05-24
CVE-2020-25688 [LOW] CWE-798 GHSA-xm77-mpc2-5mxx: A flaw was found in rhacm versions before 2
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.
Red Hat
rhacm: certificate re-use in grcuiapi and topologyapi
vendor_redhat·2020-11-05·CVSS 3.5
CVE-2020-25688 [LOW] CWE-321 rhacm: certificate re-use in grcuiapi and topologyapi
rhacm: certificate re-use in grcuiapi and topologyapi
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a cluster, they could use the private key to decode API requests that should be protected by TLS sessions, potentially obtaining information they would not otherwise be able to. These certificates are not used for service authentication, so no opportunity for impersonation or active MITM attacks were made possible.
A flaw was found in rhacm. Two internal service APIs were incorrectly provisioned using a test certificate from the source repos
No detection rules found.
No public exploits indexed.
2020-11-23
Published