VulnerabilityModified
CVE-2017-15137
This could allow a user with access to OpenShift to run images from registries that should not be allowed.
MEDIUM 5.3EPSS 0.99%
Does this matter?
Lower severity and a low EPSS score (0.99%). Track it; it rarely justifies an emergency change on its own.
Description
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.99% probability · 61th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/openshift · redhat/openshift container platform
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHBA-2018:0489Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15137Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHBA-2018:0489Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15137Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.