Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-1632


An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.


Published

2022-09-01T21:15:08.957

Last Modified

2024-11-21T06:41:08.257

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-295
  • Type: Secondary
    CWE-295

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat ansible_automation_platform 2.0 Yes
Application redhat openshift_container_platform 4.0 Yes
Operating System fedoraproject fedora 34 Yes
Operating System fedoraproject fedora 35 Yes

References