CVE-2019-10214: Medium severity Buildah Project Buildah vulnerability
The containers/image library used by container tools; Podman, Builah, and Skopeo in Red Hat Enterprise Linux 8, and CRI-O in OpenShift Container Platform does not enforce TLS connections to the container registry authorization service [1]. An attacker could use this vulnerability launch a MiTM attack, and steal login credentials, or bearer tokens.
Upstream issue:
https://github.com/containers/image/issues/654
Upstream patch:
https://github.com/containers/image/pull/669
[1] https://docs.docker.com/registry/spec/auth/token/
Other sources
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-10214.
What is the severity of CVE-2019-10214?
The severity of CVE-2019-10214 is medium.
Which software is affected by CVE-2019-10214?
The software affected by CVE-2019-10214 includes Podman, Buildah, Skopeo, CRI-O, Red Hat Enterprise Linux version 8, and OpenShift Container Platform.
How can an attacker exploit CVE-2019-10214?
An attacker could exploit CVE-2019-10214 by launching a man-in-the-middle attack to intercept and modify container images during podman pull or skopeo copy operations.
How can I fix CVE-2019-10214?
To fix CVE-2019-10214, update the affected software to version 3.0.0 or higher.