SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1069

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems.

HIGH 7.1EPSS 0.58%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.

CVSS 3.0
7.1 HIGHCVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.58% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-284, CWE-732
Affected
redhat/openshift
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.