CVE-2016-7075: High severity kubernetes dashboard vulnerability
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Other sources
Upstream reports: Clients using SSL certs for auth show the subject CN of their intermediate cert not their entity cert.
Reference URL: https://github.com/kubernetes/kubernetes/issues/34517
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-7075?
CVE-2016-7075 has a high severity rating due to its potential to bypass authentication mechanisms.
How do I fix CVE-2016-7075?
To mitigate CVE-2016-7075, ensure that you are using the latest versions of Kubernetes or OpenShift that have addressed this vulnerability.
Which software is affected by CVE-2016-7075?
CVE-2016-7075 affects Kubernetes and specific versions of Red Hat OpenShift Enterprise 3.1, 3.2, and 3.3.
What type of attack can be executed using CVE-2016-7075?
An attacker can leverage CVE-2016-7075 to bypass authentication by employing a specially crafted X.509 certificate.
What is the primary issue with CVE-2016-7075?
The primary issue with CVE-2016-7075 is the improper validation of X.509 client intermediate certificate host name fields.