CVE-2016-2160
HIGHRed Hat OpenShift 3.2 Authenticated Remote Code Execution via STI Builder
Title source: llmDescription
Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.
References (3)
Core 3
Core References
Patch x_refsource_confirm
https://github.com/openshift/origin/pull/7864
Vendor Advisory vendor-advisory
x_refsource_redhat
https://access.redhat.com/errata/RHSA-2016:1064
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1316127
Scores
CVSS v3
8.8
EPSS
0.0406
EPSS Percentile
89.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (2)
redhat/openshift
3.2
redhat/openshift_origin
Published
Jun 08, 2016
Tracked Since
Feb 18, 2026