Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-14632

Опубликовано: 06 сент. 2018
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

An out of bounds write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform 3.x. An attacker can use this flaw to cause a denial of service attack on the Openshift master API service which provides cluster management.

Отчет

A multi-master Openshift Container Platform cluster is more resilient, however a sustained attack would still have an important impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.2atomic-openshiftAffected
Red Hat OpenShift Container Platform 3.3atomic-openshiftAffected
Red Hat OpenShift Container Platform 3.4atomic-openshiftAffected
Red Hat OpenShift Container Platform 3.5atomic-openshiftAffected
Red Hat OpenShift Container Platform 4openshiftNot affected
Red Hat OpenShift Enterprise 3.0openshiftAffected
Red Hat OpenShift Container Platform 3.10atomic-openshiftFixedRHSA-2018:270911.11.2018
Red Hat OpenShift Container Platform 3.11atomic-openshiftFixedRHBA-2018:265211.10.2018
Red Hat OpenShift Container Platform 3.6atomic-openshiftFixedRHSA-2018:265426.09.2018
Red Hat OpenShift Container Platform 3.7atomic-openshiftFixedRHSA-2018:290621.11.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1625885atomic-openshift: oc patch with json causes masterapi service crash

EPSS

Процентиль: 65%
0.00486
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
больше 7 лет назад

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

CVSS3: 7.7
nvd
больше 7 лет назад

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

CVSS3: 7.7
github
больше 3 лет назад

JSON-Patch Out-of-bounds Write vulnerability

EPSS

Процентиль: 65%
0.00486
Низкий

7.7 High

CVSS3