PT-2018-10252 · Red Hat · Openshift Enterprise
Michael Hanselmann
+1
·
Published
2018-06-12
·
Updated
2023-02-06
·
CVE-2018-1103
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Openshift Enterprise source-to-image versions prior to 1.1.10
Description
The issue is related to improper validation of user input and path sanitization. Archives containing relative file paths can cause files to be written or overwritten outside of the target directory. An attacker could trick a user into using a command to copy files locally from a pod, potentially overriding files outside the target directory.
Recommendations
For versions prior to 1.1.10, update to version 1.1.10 or later to resolve the issue. As a temporary workaround, consider restricting the use of the command to copy files locally from a pod to minimize the risk of exploitation. Avoid using archives containing relative file paths in the affected
github.com/openshift/source-to-image/pkg/tar package until the issue is resolved.Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openshift Enterprise