CVE-2013-4364
published 2018-01-08CVE-2013-4364: (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to…
PriorityP431high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.9th percentile
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenShift: openshift-origin-broker-util incorrect temporary file usage
vendor_redhat·2014-07-07·CVSS 7.8
CVE-2013-4364 [HIGH] CWE-377 OpenShift: openshift-origin-broker-util incorrect temporary file usage
OpenShift: openshift-origin-broker-util incorrect temporary file usage
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
Statement: On OpenShift Enterprise 2.1 the broker and node should be installed on separate systems, as such there should not be any local untrusted users on the broker system(s). This issue is not currently planned to be addressed in future updates. For additional information, refer to
the Issue Severity Classification:
https://access.redhat.com/security/updates/classification/.
Package: openshift-origin-broker-util (OpenShift Enterprise 1) - Will not fix
Package: openshift-origin-broke
GHSA
GHSA-5pv6-62pr-4gfr: (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local us
ghsa_unreviewed·2022-05-14
CVE-2013-4364 [HIGH] CWE-59 GHSA-5pv6-62pr-4gfr: (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local us
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
No detection rules found.
No public exploits indexed.
2018-01-08
Published