CVE-2019-10214

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 61%
Affected Products (NVD)
VendorProductVersion
buildah_projectbuildah
-
libpod_projectlibpod
-
redhatopenshift_container_platform
4.1
skopeo_projectskopeo
-
redhatenterprise_linux
8.0
opensuseleap
15.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-github-containers-image
bookworm
5.23.1-4
fixed
bullseye
5.10.3-1
fixed
sid
5.32.2-5
fixed
trixie
5.32.2-5
fixed
singularity-container
sid
4.1.5+ds3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-containers-image
bionic
dne
focal
needs-triage
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
dne
xenial
dne
singularity-container
bionic
needs-triage
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
needs-triage
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
buildah
suse enterprise sap 15 SP1
1.17.0-3.6.1
fixed
suse enterprise sap 15 SP2
1.7.1-3.3.1
fixed
suse enterprise sap 15 SP3
1.7.1-3.3.1
fixed
suse enterprise sap 15 SP4
1.23.1-150400.1.17
fixed
suse enterprise sap 15 SP5
1.29.1-150500.1.13
fixed
suse enterprise sap 15 SP6
1.34.1-150500.3.7.1
fixed
suse enterprise sap 15 SP7
1.35.5-150500.3.34.1
fixed
suse enterprise server 15 SP1
1.17.0-3.6.1
fixed
suse enterprise server 15 SP2
1.7.1-3.3.1
fixed
suse enterprise server 15 SP3
1.7.1-3.3.1
fixed
suse enterprise server 15 SP4
1.23.1-150400.1.17
fixed
suse enterprise server 15 SP5
1.29.1-150500.1.13
fixed
suse enterprise server 15 SP6
1.34.1-150500.3.7.1
fixed
suse enterprise server 15 SP7
1.35.5-150500.3.34.1
fixed
podman
suse enterprise sap 15 SP1
1.4.4-4.11.1
fixed
suse enterprise sap 15 SP2
1.4.4-4.11.1
fixed
suse enterprise sap 15 SP3
1.4.4-4.11.1
fixed
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP1
1.4.4-4.11.1
fixed
suse enterprise server 15 SP2
1.4.4-4.11.1
fixed
suse enterprise server 15 SP3
1.4.4-4.11.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-cni-config
suse enterprise sap 15 SP1
1.4.4-4.11.1
fixed
suse enterprise sap 15 SP2
1.4.4-4.11.1
fixed
suse enterprise sap 15 SP3
1.4.4-4.11.1
fixed
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP1
1.4.4-4.11.1
fixed
suse enterprise server 15 SP2
1.4.4-4.11.1
fixed
suse enterprise server 15 SP3
1.4.4-4.11.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
podman-docker
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podman-remote
suse enterprise sap 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise sap 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP4
3.4.4-150400.2.14
fixed
suse enterprise server 15 SP5
4.4.4-150500.1.4
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
podmansh
suse enterprise sap 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise sap 15 SP7
4.9.5-150500.3.40.1
fixed
suse enterprise server 15 SP6
4.8.3-150500.3.9.1
fixed
suse enterprise server 15 SP7
4.9.5-150500.3.40.1
fixed
skopeo
suse enterprise desktop 15 SP3
0.1.41-4.11.1
fixed
suse enterprise desktop 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise desktop 15 SP7
1.14.4-150300.11.22.1
fixed
suse enterprise sap 15
0.1.32-4.8.1
fixed
suse enterprise sap 15 SP3
0.1.41-4.11.1
fixed
suse enterprise sap 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise sap 15 SP7
1.14.4-150300.11.22.1
fixed
suse enterprise server 15
0.1.32-4.8.1
fixed
suse enterprise server 15 SP3
0.1.41-4.11.1
fixed
suse enterprise server 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise server 15 SP7
1.14.4-150300.11.22.1
fixed
skopeo-bash-completion
suse enterprise desktop 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise desktop 15 SP7
1.14.4-150300.11.22.1
fixed
suse enterprise sap 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise sap 15 SP7
1.14.4-150300.11.22.1
fixed
suse enterprise server 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise server 15 SP7
1.14.4-150300.11.22.1
fixed
skopeo-zsh-completion
suse enterprise desktop 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise desktop 15 SP7
1.14.4-150300.11.22.1
fixed
suse enterprise sap 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise sap 15 SP7
1.14.4-150300.11.22.1
fixed
suse enterprise server 15 SP6
1.12.0-150300.11.5.1
fixed
suse enterprise server 15 SP7
1.14.4-150300.11.22.1
fixed