Описание
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
An improper authorization flaw in the atomic-openshift component of Openshift Container Platform 3.7 and earlier allows a user with cluster-reader project viewer permissions to trigger an application build. An attacker could use this flaw to trigger a build of an application when that should be restricted.
Отчет
The OpenShift Enterprise cluster-read can access webhook tokens, [1], which would allow an attacker with cluster-reader permissions, [2], or project viewer, [3], to view confidential webhook tokens. [1] https://docs.openshift.com/container-platform/3.7/dev_guide/builds/triggering_builds.html#webhook-triggers [2] https://docs.openshift.com/container-platform/3.7/admin_guide/manage_rbac.html [3] https://docs.openshift.com/container-platform/3.7/admin_solutions/user_role_mgmt.html#adding-a-role-to-a-user
Меры по смягчению последствий
Don't use webhook tokens to trigger builds. Alternatively don't rely on project viewer, or cluster-reader permissions from preventing those users from running builds.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.2 | atomic-openshift | Will not fix | ||
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Will not fix | ||
| Red Hat OpenShift Container Platform 3.9 | ansible-asb-modules | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | ansible-kubernetes-modules | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | ansible-service-broker | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | apb | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | apb-base-scripts | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-dockerregistry | Fixed | RHBA-2018:0489 | 28.03.2018 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-web-console | Fixed | RHBA-2018:0489 | 28.03.2018 |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS3
Связанные уязвимости
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
EPSS
5 Medium
CVSS3