CRITICAL 9.3
GHSA-8g5p-jxp9-457c
Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication
빠른 조치
GHSA-8g5p-jxp9-457c — github.com/kubev2v/assisted-migration-agent: 아래 명령으로 수정 버전으로 올리세요.
go get github.com/kubev2v/assisted-migration-agent@v0.16.0 상세
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Middle (MITM) attacker to intercept and harvest vCenter administrator credentials. This can lead to unauthorized access to vCenter.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Go / github.com/kubev2v/assisted-migration-agent
최초 영향 버전:
0 수정 버전: 0.16.0 수정
go get github.com/kubev2v/assisted-migration-agent@v0.16.0 참고
- https://nvd.nist.gov/vuln/detail/CVE-2026-53475 [ADVISORY]
- https://github.com/kubev2v/assisted-migration-agent/pull/268 [WEB]
- https://github.com/kubev2v/assisted-migration-agent/commit/b940fec9f5032a0801e994054d30e81d64b2942a [WEB]
- https://access.redhat.com/security/cve/CVE-2026-53475 [WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2487232 [WEB]
- https://github.com/kubev2v/assisted-migration-agent [PACKAGE]