Show filters
14 Total Results
Displaying 11-14 of 14
Sort by:
Attacker Value
Unknown
CVE-2017-15137
Disclosure Date: July 16, 2018 (last updated November 27, 2024)
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
0
Attacker Value
Unknown
CVE-2018-10843
Disclosure Date: July 02, 2018 (last updated November 26, 2024)
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.
0
Attacker Value
Unknown
CVE-2018-1102
Disclosure Date: April 30, 2018 (last updated November 26, 2024)
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
0
Attacker Value
Unknown
CVE-2017-7534
Disclosure Date: April 11, 2018 (last updated November 26, 2024)
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
0