PT-2018-12628 · Red Hat · Openshift Container Platform

Jason Shepherd

+1

·

Published

2018-09-06

·

Updated

2023-02-07

·

CVE-2018-14632

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenShift Container Platform versions prior to 3.7
Description The issue is related to an out-of-bounds write that can occur when patching an OpenShift object using the oc patch functionality. This can be exploited to cause a denial of service attack on the OpenShift master API service, which provides cluster management. A malicious JSON patch can cause a panic due to an out-of-bounds write attempt, potentially serving as a denial of service vector if exposed to arbitrary user input.
Recommendations For OpenShift Container Platform versions prior to 3.7, update to version 3.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the oc patch functionality to minimize the risk of exploitation. Avoid using the oc patch command with untrusted input until the issue is resolved.

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2018-14632
GHSA-GXHV-3HWF-WJP9
GO-2021-0076
RHSA-2018:2654
RHSA-2018:2709
RHSA-2018:2906
RHSA-2018:2908

Affected Products

Openshift Container Platform