VDB
KO
CRITICAL 9.3

GHSA-8g5p-jxp9-457c

Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication

Quick fix

GHSA-8g5p-jxp9-457c — github.com/kubev2v/assisted-migration-agent: upgrade to the fixed version with the command below.

go get github.com/kubev2v/assisted-migration-agent@v0.16.0

Details

A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/kubev2v/assisted-migration-agent
Introduced in: 0 Fixed in: 0.16.0
Fix go get github.com/kubev2v/assisted-migration-agent@v0.16.0

References