CVE-2019-10150
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.9epss 1.4%
exploitation probability
1.4%top 29% of all CVEs
observed exploitation
nono source reports it
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.
CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Affected products
redhat · atomic-openshiftReferences
https://access.redhat.com/errata/RHSA-2019:2989https://access.redhat.com/errata/RHSA-2019:3007https://access.redhat.com/errata/RHSA-2019:3143https://access.redhat.com/errata/RHSA-2019:3811https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication