CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.9. See the original NVD description below for full technical details.
CVE
CVE-2019-10150
Severity
MEDIUM
CVSS
5.9
EPSS
1.39%
Original NVD Description
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.
Related CVEs
Other vulnerabilities affecting the same vendor(s)