CVE-2018-1069

HIGH

Redhat Openshift - Improper Access Control

Title source: rule
STIX 2.1

Description

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.

References (2)

Core 2
Core References
Issue Tracking, Mitigation x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1552987
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103364

Scores

CVSS v3 7.1
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284 CWE-732
Status published
Products (1)
redhat/openshift 3.7
Published Mar 09, 2018
Tracked Since Feb 18, 2026