Back

MEDIUM

containers/image: not enforcing TLS when sending username+password credentials to token servers leading to credential disclosure

Published Nov 25, 2019

Description

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.

Affected products

Remediation

No remediation recorded yet.

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 25, 2019
Updated Aug 4, 2024
Reserved Mar 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 9, 2019
ENISA EUVD
Assigner redhat
Published Nov 25, 2019
Updated Aug 4, 2024
Exploited since n/a
EUVD-2022-0905 GHSA-85P9-J7C9-V4GR