PT-2016-5039 · Red Hat · Openshift Origin+1
Adam Mariš
·
Published
2016-06-08
·
Updated
2016-06-09
·
CVE-2016-2160
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat OpenShift Enterprise version 3.2
OpenShift Origin (affected versions not specified)
Description
The issue allows remote authenticated users to execute commands with root privileges. This is achieved by changing the root password in an sti builder image.
Recommendations
For Red Hat OpenShift Enterprise version 3.2, update the system to prevent remote authenticated users from executing commands with root privileges.
For OpenShift Origin, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Origin
Red Hat Openshift Enterprise