{"id":"CVE-2016-7075","details":"It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.","modified":"2026-03-13T22:21:44.836755Z","published":"2018-09-10T14:29:00.800Z","related":["CGA-xvwc-98qj-pvxr"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2016:2064"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7075"},{"type":"FIX","url":"https://github.com/kubernetes/kubernetes/issues/34517"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"0"},{"last_affected":"3.1"}]},{"events":[{"introduced":"0"},{"last_affected":"3.2"}]},{"events":[{"introduced":"0"},{"last_affected":"3.3"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7075.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}