Cleartext transmission of sensitive information in Container Projects image library - CVE-2019-10214
Published: September 16, 2019
Vulnerability identifier: #VU21141
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10214
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to containers/image library library does not enforce TLS connection by default. A remote attacker with ability to perform MitM attack can gain accecss to sensitive information.
Affected software
Container Projects image library
buildah
Red Hat OpenShift Container Platform
Container Projects skopeo
Red Hat Enterprise Linux for x86_64
Opensuse
buildah
Red Hat OpenShift Container Platform
Container Projects skopeo
Red Hat Enterprise Linux for x86_64
Opensuse
How to mitigate CVE-2019-10214
Install updates from vendor's website.
Container Projects image library - update to 3.0.0
buildah - update to 1.10.0
Container Projects skopeo - update to 0.1.38
buildah - update to 1.10.0
Container Projects skopeo - update to 0.1.38
External References
Related Security Bulletins
- Information disclosure in Container Projects image library
- OpenSUSE Linux update for skopeo
- OpenSUSE Linux update for buildah
- Information disclosure in Container Projects skopeo
- Information disclosure in Container Projects buildah
- OpenSUSE Linux update for podman
- Red Hat update for OpenShift Container Platform 3.11
- OpenSUSE Linux update for skopeo
- Red Hat update for OpenShift Container Platform 4.1.17 cri-o
- Red Hat update for container-tools:1.0
- Red Hat update for container-tools:rhel8
- Red Hat update for OpenShift Container Platform 3.9 cri-o
- OpenSUSE Linux update for skopeo
- OpenSUSE Linux update for kubernetes
- OpenSUSE Linux update for SUSE Manager Client Tools