Back

HIGH

kubevirt/virt-cdi-importer: improper TLS certificate validation

Published Mar 25, 2019

Description

Kubevirt/virt-cdi-importer, versions 1.4.0 to 1.5.3 inclusive, were reported to disable TLS certificate validation when importing data into PVCs from container registries. This could enable man-in-the-middle attacks between a container registry and the virt-cdi-component, leading to possible undetected tampering of trusted container image content.

Affected products

Remediation

Red Hat statement

No public release of Red Hat Container Native Virtualization is affected by this flaw.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 25, 2019
Updated Aug 4, 2024
Reserved Jan 3, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 26, 2019