Vulnerability Name: | CVE-2018-1069 (CCN-140136) | ||||||||||||
Assigned: | 2017-12-04 | ||||||||||||
Published: | 2017-12-04 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem. | ||||||||||||
CVSS v3 Severity: | 7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) 6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.4 Medium (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-732 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-1069 Source: BID Type: Third Party Advisory, VDB Entry 103364 Source: CCN Type: BID-103364 Red Hat OpenShift Enterprise CVE-2018-1069 Privilege Escalation Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1552987 (CVE-2018-1069) CVE-2018-1069 Networking: container networking does not prevent access to network resources Source: CONFIRM Type: Issue Tracking, Mitigation https://bugzilla.redhat.com/show_bug.cgi?id=1552987 Source: XF Type: UNKNOWN redhat-cve20181069-weak-security(140136) | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
BACK |