CVE-2019-14845: Medium severity red hat openshift vulnerability
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.
Other sources
A vulnerability was found in OpenShift builds. Builds which extract source from a container image bypass TLS hostname verification. An attacker can take advantage of this by launching a man-in-the-middle attack and injecting malicious content.
References:
https://github.com/openshift/builder/blob/04c78176099139a5d229578a9a98ed2e1d17a19d/pkg/build/builder/source.go#L383-L385
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14845?
CVE-2019-14845 has a medium severity rating due to its potential for man-in-the-middle attacks.
How can I fix CVE-2019-14845?
To fix CVE-2019-14845, upgrade your OpenShift environment to version 4.4 or later.
What versions of OpenShift are affected by CVE-2019-14845?
CVE-2019-14845 affects OpenShift builds from version 4.1 to 4.3.
What type of attack is possible with CVE-2019-14845?
CVE-2019-14845 allows an attacker to conduct man-in-the-middle attacks by bypassing TLS hostname verification.
What is the impact of CVE-2019-14845 on my deployment?
The impact of CVE-2019-14845 can include the injection of malicious content during the build process.