CVE-2019-10150

Source
https://cve.org/CVERecord?id=CVE-2019-10150
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10150.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10150
Downstream
Published
2019-06-12T14:29:02.867Z
Modified
2026-03-13T11:30:05.199384Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "3.6"
            },
            {
                "last_affected": "4.1"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10150.json"