PT-2016-5039 · Red Hat · Openshift Origin+1

Adam Mariš

·

Published

2016-06-08

·

Updated

2016-06-09

·

CVE-2016-2160

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat OpenShift Enterprise version 3.2 OpenShift Origin (affected versions not specified)
Description The issue allows remote authenticated users to execute commands with root privileges. This is achieved by changing the root password in an sti builder image.
Recommendations For Red Hat OpenShift Enterprise version 3.2, update the system to prevent remote authenticated users from executing commands with root privileges. For OpenShift Origin, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-2160
RHSA-2016:1064

Affected Products

Openshift Origin
Red Hat Openshift Enterprise