CVE-2019-14845

A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.
Configurations

Configuration 1

cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:*

Information

Published : 2019-10-08 07:15

Updated : 2023-02-12 11:35


NVD link : CVE-2019-14845

Mitre link : CVE-2019-14845

Products Affected
No products.
CWE
CWE-494

Download of Code Without Integrity Check