|
|
Log in / Subscribe / Register

atomic-openshift: authentication bypass

Package(s):atomic-openshift CVE #(s):CVE-2016-7075
Created:October 18, 2016 Updated:October 19, 2016
Description: From the Red Hat advisory:

It was found that Kubernetes did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

Alerts:
Red Hat RHSA-2016:2064-01 atomic-openshift 2016-10-17

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds