Vulnerability Details CVE-2016-7075
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 6.8
Products affected by CVE-2016-7075
-
cpe:2.3:a:kubernetes:kubernetes:-
-
cpe:2.3:a:redhat:openshift:3.1
-
cpe:2.3:a:redhat:openshift:3.2
-
cpe:2.3:a:redhat:openshift:3.3