PT-2018-12628 · Red Hat · Openshift Container Platform
Jason Shepherd
+1
·
Published
2018-09-06
·
Updated
2023-02-07
·
CVE-2018-14632
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenShift Container Platform versions prior to 3.7
Description
The issue is related to an out-of-bounds write that can occur when patching an OpenShift object using the
oc patch functionality. This can be exploited to cause a denial of service attack on the OpenShift master API service, which provides cluster management. A malicious JSON patch can cause a panic due to an out-of-bounds write attempt, potentially serving as a denial of service vector if exposed to arbitrary user input.Recommendations
For OpenShift Container Platform versions prior to 3.7, update to version 3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the
oc patch functionality to minimize the risk of exploitation. Avoid using the oc patch command with untrusted input until the issue is resolved.Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Container Platform