PT-2016-1270 · Red Hat · Openshift

Jwforres

·

Published

2016-02-03

·

Updated

2024-08-21

·

CVE-2016-1906

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Openshift (affected versions not specified)
Description The issue is related to a lack of access control in the interface of a cluster management tool for Kubernetes virtual machines, allowing remote attackers to elevate their privileges. This can be achieved by editing a build configuration. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2016-00543
CVE-2016-1906
GHSA-M3FM-H5JP-Q79P
GO-2022-0854
RHSA-2016:0070
RHSA-2016:0351

Affected Products

Openshift