Cleartext transmission of sensitive information in Container Projects image library - CVE-2019-10214

 

Cleartext transmission of sensitive information in Container Projects image library - CVE-2019-10214

Published: September 16, 2019


Vulnerability identifier: #VU21141
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10214
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to containers/image library library does not enforce TLS connection by default. A remote attacker with ability to perform MitM attack can gain accecss to sensitive information.


Affected software

Container Projects image library
buildah
Red Hat OpenShift Container Platform
Container Projects skopeo
Red Hat Enterprise Linux for x86_64
Opensuse

How to mitigate CVE-2019-10214

Install updates from vendor's website.

Container Projects image library - update to 3.0.0
buildah - update to 1.10.0
Container Projects skopeo - update to 0.1.38

External References

Related Security Bulletins