CVE-2014-3674

Red Hat OpenShift < 2.2 - Unauthenticated Network Resource Access via Gear Isolation Bypass

Title source: llm
STIX 2.1

Description

Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of arbitrary gears via unspecified vectors.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1906.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1796.html

Scores

EPSS 0.0202
EPSS Percentile 78.9%

Details

CWE
CWE-264
Status published
Products (16)
redhat/openshift 2.0
redhat/openshift 2.0.1
redhat/openshift 2.0.2
redhat/openshift 2.0.3
redhat/openshift 2.0.4
redhat/openshift 2.0.5
redhat/openshift 2.0.6
redhat/openshift 2.1
redhat/openshift 2.1.1
redhat/openshift 2.1.2
... and 6 more
Published Nov 13, 2014
Tracked Since Feb 18, 2026