CVE-2019-10150

Source
https://cve.org/CVERecord?id=CVE-2019-10150
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10150.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10150
Downstream
Published
2019-06-12T14:29:02.867Z
Modified
2026-02-15T07:39:44.829892Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

References

Affected packages

Git / github.com/xtermjs/xterm.js

Affected ranges

Type
GIT
Repo
https://github.com/xtermjs/xterm.js
Events

Affected versions

3.*
3.10.0
3.11.0
3.12.0
3.13.0
3.14.0
3.6.0
3.7.0
3.8.0
3.9.0
4.*
4.0.0
4.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10150.json"