It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.3"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7075.json"