PT-2026-35719 · Red Hat · Red Hat Openshift Container Platform 4
Published
2026-04-28
·
Updated
2026-04-28
·
CVE-2026-7309
CVSS v3.1
4.3
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
A flaw was found in the OpenShift Container Platform build system. A user with the
edit ClusterRole can inject arbitrary environment variables, such as LD PRELOAD or http proxy, into docker-build containers through the buildconfigs/instantiate API. This incomplete fix for a previous vulnerability allows for information disclosure, specifically impacting the confidentiality of build traffic.Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Openshift Container Platform 4