SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-15137

This could allow a user with access to OpenShift to run images from registries that should not be allowed.

MEDIUM 5.3EPSS 0.99%

Does this matter?

Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.

Description

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
0.99% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
redhat/openshift · redhat/openshift container platform
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.