CVE-2019-3818
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327
- Affected
- kube-rbac-proxy project/kube-rbac-proxy · redhat/openshift container platform
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/106744Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-3818Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3818Issue Tracking, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/106744Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2019-3818Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3818Issue Tracking, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.