CVE-2016-7075

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
10/09/2018
Last modified:
12/02/2023

Description

It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kubernetes:kubernetes:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*
cpe:2.3:a:redhat:openshift:3.2:*:*:*:enterprise:*:*:*
cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:*