Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2149

Опубликовано: 09 мар. 2016
Источник: redhat
CVSS2: 3.5
EPSS Низкий

Описание

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.

It was found that OpenShift Enterprise would disclose log file contents from reclaimed namespaces. An attacker could create a new namespace to access log files present in a previously deleted namespace using the same name.

Дополнительная информация

Статус:

Low
Дефект:
CWE-285
https://bugzilla.redhat.com/show_bug.cgi?id=13162673: logs from a deleted namespace can be revealed if a new namespace with the same name is created

EPSS

Процентиль: 45%
0.00224
Низкий

3.5 Low

CVSS2

Связанные уязвимости

CVSS3: 6.5
nvd
больше 9 лет назад

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.

CVSS3: 6.5
github
больше 3 лет назад

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.

EPSS

Процентиль: 45%
0.00224
Низкий

3.5 Low

CVSS2