|
3 | 3 | "enisaUuid": "7dda2317-88fe-356d-a32c-eafd01df48b2", |
4 | 4 | "description": "A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.", |
5 | 5 | "datePublished": "May 29, 2026, 9:50:44 AM", |
6 | | - "dateUpdated": "Jul 15, 2026, 12:50:13 AM", |
| 6 | + "dateUpdated": "Jul 20, 2026, 1:28:50 AM", |
7 | 7 | "baseScore": 7.4, |
8 | 8 | "baseScoreVersion": "3.1", |
9 | 9 | "baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", |
10 | | - "references": "https://access.redhat.com/errata/RHSA-2026:27009\nhttps://access.redhat.com/errata/RHSA-2026:27044\nhttps://access.redhat.com/errata/RHSA-2026:27063\nhttps://access.redhat.com/security/cve/CVE-2026-46579\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2483181\n", |
| 10 | + "references": "https://access.redhat.com/errata/RHSA-2026:27009\nhttps://access.redhat.com/errata/RHSA-2026:27044\nhttps://access.redhat.com/errata/RHSA-2026:27063\nhttps://access.redhat.com/errata/RHSA-2026:37580\nhttps://access.redhat.com/security/cve/CVE-2026-46579\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2483181\n", |
11 | 11 | "aliases": "CVE-2026-46579\nGHSA-ccmj-8c3p-4qwj\n", |
12 | 12 | "assigner": "redhat", |
13 | | - "epss": 0.23, |
| 13 | + "epss": 0.24, |
14 | 14 | "enisaIdProduct": [ |
| 15 | + { |
| 16 | + "id": "01d1af5b-84ab-3387-b2b7-5e3cfd6b1e5a", |
| 17 | + "product": { |
| 18 | + "name": "Red Hat OpenShift Container Platform 4.2", |
| 19 | + "vendor": { |
| 20 | + "name": "Red Hat" |
| 21 | + } |
| 22 | + }, |
| 23 | + "product_version": "patch: 1781639027" |
| 24 | + }, |
15 | 25 | { |
16 | 26 | "id": "055fa2d9-202e-3de9-a71c-b3e9281c038b", |
17 | 27 | "product": { |
|
22 | 32 | }, |
23 | 33 | "product_version": "patch: 1781639027" |
24 | 34 | }, |
| 35 | + { |
| 36 | + "id": "3d33853a-8a8d-35f3-8e87-b6303a5ebbc4", |
| 37 | + "product": { |
| 38 | + "name": "Red Hat OpenShift Container Platform 4.19", |
| 39 | + "vendor": { |
| 40 | + "name": "Red Hat" |
| 41 | + } |
| 42 | + }, |
| 43 | + "product_version": "patch: 1783445642" |
| 44 | + }, |
25 | 45 | { |
26 | 46 | "id": "61b5f1f6-1a07-3f2f-807a-6eff3d7f6af0", |
27 | 47 | "product": { |
|
0 commit comments