CVE-2019-10150

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/06/2019
Last modified:
12/02/2023

Description

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* 3.6 (including) 4.1 (including)