CVE-2019-10214: Buildah Project Buildah
Medium severity, CVSS 5.9. EPSS: 1.6% chance of exploitation in the next 30 days.
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Affected products
- Buildah Project Buildah: affected versions not specified
- Libpod Project Libpod: affected versions not specified
- Opensuse Leap: version 15.1 only
- Red Hat Enterprise Linux: version 8.0 only
- Red Hat Openshift Container Platform: version 4.1 only
- Skopeo Project Skopeo: affected versions not specified
Published 2019-11-25. Last modified 2026-06-17.