SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-2149

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.

MEDIUM 6.5EPSS 1.54%

Does this matter?

Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.

Description

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.54% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
redhat/openshift
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.