VulnerabilityModified
CVE-2018-1069
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems.
HIGH 7.1EPSS 0.58%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.
- CVSS 3.0
- 7.1 HIGHCVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-732
- Affected
- redhat/openshift
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/103364Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1552987Issue Tracking, Mitigation
- http://www.securityfocus.com/bid/103364Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1552987Issue Tracking, Mitigation
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.