SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14632

An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

HIGH 7.7EPSS 1.95%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

CVSS 3.1
7.7 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS
1.95% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
redhat/openshift container platform · starcounter-jack/json-patch
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.