Bug 1668961 (CVE-2019-3818)
Summary: | CVE-2019-3818 kube-rbac-proxy: Improper application of config allows for insecure ciphers and TLS 1.0 | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Sam Fowler <sfowler> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | unspecified | CC: | ahardin, bleanhar, bmontgom, ccoleman, dedgar, eparis, jburrell, jgoulding, jokerman, mchappel, nstielau, security-response-team, sfowler, sponnaga |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | kube-rbac-proxy 0.4.1 | Doc Type: | If docs needed, set a value |
Doc Text: |
The kube-rbac-proxy container, as used in Red Hat OpenShift Container Platform, does not honor TLS configurations allowing for the use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption of the data stream.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2021-10-27 03:23:24 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1669378, 1669379 | ||
Bug Blocks: | 1668962 |
Description
Sam Fowler
2019-01-24 01:13:01 UTC
Acknowledgments: Name: Frederic Branczyk (Red Hat), Matthias Loibl (Red Hat), Max Inden (Red Hat) This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.11 Via RHBA-2019:0327 https://access.redhat.com/errata/RHBA-2019:0327 |