CVE-2019-14845

A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-10-08 19:15

Updated : 2024-02-28 17:28


NVD link : CVE-2019-14845

Mitre link : CVE-2019-14845

CVE.ORG link : CVE-2019-14845


JSON object : View

Products Affected

redhat

  • openshift
CWE
CWE-494

Download of Code Without Integrity Check