Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-1103

Опубликовано: 12 июн. 2018
Источник: nvd
CVSS3: 6.1
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user into using the command to copy files locally, from a pod, could override files outside of the target directory of the command.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:source-to-image:*:*:*:*:*:*:*:*
Версия до 1.1.10 (исключая)

EPSS

Процентиль: 50%
0.00268
Низкий

6.1 Medium

CVSS3

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-22
CWE-20

Связанные уязвимости

CVSS3: 6.1
redhat
больше 7 лет назад

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user into using the command to copy files locally, from a pod, could override files outside of the target directory of the command.

CVSS3: 6.5
github
около 3 лет назад

Openshift Enterprise source-to-image vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip)

EPSS

Процентиль: 50%
0.00268
Низкий

6.1 Medium

CVSS3

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-22
CWE-20