PT-2018-10054 · Red Hat+1 · Red Hat Openshift Enterprise+2

Andreas Skoglund

·

Published

2018-03-09

·

Updated

2019-10-09

·

CVE-2018-1069

CVSS v3.1

7.1

High

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Red Hat OpenShift Enterprise version 3.7
Description The issue allows an attacker to override access control for container network filesystems, specifically for GlusterFS and NFS. This could enable the attacker to read and write any data on the network filesystem by overriding the UserId and GroupId.
Recommendations For Red Hat OpenShift Enterprise version 3.7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1069

Affected Products

Glusterfs
Nfs
Red Hat Openshift Enterprise