CVE-2016-2160

HIGH

Red Hat OpenShift 3.2 Authenticated Remote Code Execution via STI Builder

Title source: llm
STIX 2.1

Description

Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1064
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1316127

Scores

CVSS v3 8.8
EPSS 0.0406
EPSS Percentile 89.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (2)
redhat/openshift 3.2
redhat/openshift_origin
Published Jun 08, 2016
Tracked Since Feb 18, 2026