VulnerabilityModified
CVE-2016-8631
An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
HIGH 7.7EPSS 1.10%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
- CVSS 3.0
- 7.7 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/openshift
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/94110Third Party Advisory, VDB Entry, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:2696Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631Issue Tracking, Vendor Advisory
- http://www.securityfocus.com/bid/94110Third Party Advisory, VDB Entry, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:2696Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.