First published: Tue Jul 23 2019(Updated: )
The containers/image library used by container tools; Podman, Builah, and Skopeo in Red Hat Enterprise Linux 8, and CRI-O in OpenShift Container Platform does not enforce TLS connections to the container registry authorization service [1]. An attacker could use this vulnerability launch a MiTM attack, and steal login credentials, or bearer tokens. Upstream issue: <a href="https://github.com/containers/image/issues/654">https://github.com/containers/image/issues/654</a> Upstream patch: <a href="https://github.com/containers/image/pull/669">https://github.com/containers/image/pull/669</a> [1] <a href="https://docs.docker.com/registry/spec/auth/token/">https://docs.docker.com/registry/spec/auth/token/</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/containers/image | <3.0.0 | 3.0.0 |
redhat/containers-image | <3.0.0 | 3.0.0 |
redhat/atomic-openshift | <0:3.10.175-1.git.0.f9f0e81.el7 | 0:3.10.175-1.git.0.f9f0e81.el7 |
redhat/cri-o | <0:1.10.6-2.rhaos3.10.git56d7d9a.el7 | 0:1.10.6-2.rhaos3.10.git56d7d9a.el7 |
redhat/cri-o | <0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7 | 0:1.11.16-0.2.dev.rhaos3.11.git3f89eba.el7 |
redhat/cri-o | <0:1.9.16-5.git858756d.el7 | 0:1.9.16-5.git858756d.el7 |
redhat/cri-o | <0:1.13.11-0.4.dev.rhaos4.1.git9cb8f2f.el7 | 0:1.13.11-0.4.dev.rhaos4.1.git9cb8f2f.el7 |
Buildah Project Buildah | ||
Libpod Project Libpod | ||
Redhat Openshift Container Platform | =4.1 | |
Skopeo Project Skopeo | ||
Redhat Enterprise Linux | =8.0 | |
openSUSE Leap | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The vulnerability ID for this vulnerability is CVE-2019-10214.
The severity of CVE-2019-10214 is medium.
The software affected by CVE-2019-10214 includes Podman, Buildah, Skopeo, CRI-O, Red Hat Enterprise Linux version 8, and OpenShift Container Platform.
An attacker could exploit CVE-2019-10214 by launching a man-in-the-middle attack to intercept and modify container images during podman pull or skopeo copy operations.
To fix CVE-2019-10214, update the affected software to version 3.0.0 or higher.