VulnerabilityModified
CVE-2018-14632
An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
HIGH 7.7EPSS 1.95%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
- CVSS 3.1
- 7.7 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- redhat/openshift container platform · starcounter-jack/json-patch
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHBA-2018:2652Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2654Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2709Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2906Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2908Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632Issue Tracking, Patch, Vendor Advisory
- https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03#diff-65c563bba473be9d94ce4d033f74810ePatch, Third Party Advisory
- https://access.redhat.com/errata/RHBA-2018:2652Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2654Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2709Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2906Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2908Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632Issue Tracking, Patch, Vendor Advisory
- https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03#diff-65c563bba473be9d94ce4d033f74810ePatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.