It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
The product does not validate, or incorrectly validates, a certificate.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Kubernetes | Kubernetes | - (including) | - (including) |
Kubernetes | Ubuntu | groovy | * |
Kubernetes | Ubuntu | hirsute | * |
Kubernetes | Ubuntu | impish | * |
Kubernetes | Ubuntu | kinetic | * |
Kubernetes | Ubuntu | lunar | * |
Kubernetes | Ubuntu | mantic | * |
Red Hat OpenShift Container Platform 3.2 | RedHat | atomic-openshift-0:3.2.1.17-1.git.0.6d01b60.el7 | * |
Red Hat OpenShift Container Platform 3.3 | RedHat | atomic-openshift-0:3.3.0.35-1.git.0.d7bd9b6.el7 | * |
Red Hat OpenShift Enterprise 3.1 | RedHat | atomic-openshift-0:3.1.1.8-1.git.0.d469026.el7aos | * |