Red Hat Security Advisory: Red Hat OpenShift Builds 1.3
Red Hat OpenShift Builds 1.3
AI Analysis
Technical Summary
This vulnerability (CVE-2024-12797) is due to improper certificate validation in OpenSSL's implementation of RFC7250 Raw Public Key (RPK) authentication. Specifically, when RPK is enabled on both TLS clients and servers, the TLS/DTLS handshake fails to abort if the server's RPK does not match the expected key, even though SSL_VERIFY_PEER verification mode is set. This flaw allows an attacker to perform man-in-the-middle attacks by spoofing the server's identity. The vulnerability was introduced in OpenSSL 3.2, first shipped in RHEL 9.5, and affects Red Hat OpenShift Builds versions 1.2 through 1.3. RPK is disabled by default, so only users who explicitly enable RPK are affected. Ruby packages in RHEL are not affected as they do not expose RPK functions. No official fix is currently available, and mitigation options do not meet Red Hat's criteria for ease of use or applicability. Users are advised to monitor Red Hat advisories for future updates.
Potential Impact
The vulnerability allows an attacker to bypass TLS authentication by exploiting the failure to abort handshakes when the server's raw public key does not match the expected key. This can lead to man-in-the-middle attacks, enabling attackers to intercept or spoof communications that clients believe are secure. Confidentiality and integrity of communications are at high risk. Availability is not impacted. The issue affects only configurations where RPK is explicitly enabled on both client and server sides.
Mitigation Recommendations
Currently, no official fix or patch is available for this vulnerability. Red Hat advises users to upgrade to supported product versions beyond 1.3 when available. Since RPK is disabled by default, users should avoid enabling RPK on TLS clients and servers unless necessary. Clients that explicitly check the verification result via SSL_get_verify_result() and handle failures appropriately are not affected. Users should monitor Red Hat advisories for future patches or updates. No additional mitigations meeting Red Hat's criteria are currently recommended.
Red Hat Security Advisory: Red Hat OpenShift Builds 1.3
Description
Red Hat OpenShift Builds 1.3
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2024-12797) is due to improper certificate validation in OpenSSL's implementation of RFC7250 Raw Public Key (RPK) authentication. Specifically, when RPK is enabled on both TLS clients and servers, the TLS/DTLS handshake fails to abort if the server's RPK does not match the expected key, even though SSL_VERIFY_PEER verification mode is set. This flaw allows an attacker to perform man-in-the-middle attacks by spoofing the server's identity. The vulnerability was introduced in OpenSSL 3.2, first shipped in RHEL 9.5, and affects Red Hat OpenShift Builds versions 1.2 through 1.3. RPK is disabled by default, so only users who explicitly enable RPK are affected. Ruby packages in RHEL are not affected as they do not expose RPK functions. No official fix is currently available, and mitigation options do not meet Red Hat's criteria for ease of use or applicability. Users are advised to monitor Red Hat advisories for future updates.
Potential Impact
The vulnerability allows an attacker to bypass TLS authentication by exploiting the failure to abort handshakes when the server's raw public key does not match the expected key. This can lead to man-in-the-middle attacks, enabling attackers to intercept or spoof communications that clients believe are secure. Confidentiality and integrity of communications are at high risk. Availability is not impacted. The issue affects only configurations where RPK is explicitly enabled on both client and server sides.
Mitigation Recommendations
Currently, no official fix or patch is available for this vulnerability. Red Hat advises users to upgrade to supported product versions beyond 1.3 when available. Since RPK is disabled by default, users should avoid enabling RPK on TLS clients and servers unless necessary. Clients that explicitly check the verification result via SSL_get_verify_result() and handle failures appropriately are not affected. Users should monitor Red Hat advisories for future patches or updates. No additional mitigations meeting Red Hat's criteria are currently recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:2754
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-1244"]
Threat ID: 6a1f4e89e29bf47b50083a13
Added to database: 06/02/2026, 21:43:37 UTC
Last enriched: 08/16/2026, 18:27:40 UTC
Last updated: 09/10/2026, 19:24:53 UTC
Views: 295
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.