First published: Mon Mar 25 2019(Updated: )
Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of trusted container image content.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Kubevirt Containerized Data Importer | >=1.4.0<=1.5.3 | |
>=1.4.0<=1.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3841 is a vulnerability in Kubevirt/virt-cdi-importer versions 1.4.0 to 1.5.3 that disables TLS certificate validation when importing data into PVCs from container registries.
The severity of CVE-2019-3841 is high with a CVSS score of 6.8.
CVE-2019-3841 affects Kubevirt/virt-cdi-importer versions 1.4.0 to 1.5.3 by enabling man-in-the-middle attacks between a container registry and the virt-cdi-component.
CVE-2019-3841 can be exploited by an attacker who performs a man-in-the-middle attack between the container registry and the virt-cdi-component.
To fix CVE-2019-3841, upgrade Kubevirt/virt-cdi-importer to a version above 1.5.3 that addresses the TLS certificate validation issue.