CVE-2014-0163OS Command Injection in Openshift

Severity
8.8HIGHNVD
EPSS
1.4%
top 19.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 11
Latest updateMay 17

Description

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDredhat/openshift1.0, 2.0+1
CVEListV5openshift/openshiftthrough 2014-04-03

🔴Vulnerability Details

2
GHSA
GHSA-vr5q-rw5h-fh9q: Openshift has shell command injection flaws due to unsanitized data being passed into shell commands2022-05-17
CVEList
CVE-2014-0163: Openshift has shell command injection flaws due to unsanitized data being passed into shell commands2019-12-11

📋Vendor Advisories

1
Red Hat
Openshift: Multiple shell command injection flaws2014-12-03

💬Community

2
Bugzilla
CVE-2014-0163 rubygem-openshift-origin-node: Openshift: Multiple shell command injection flaws [fedora-all]2015-01-30
Bugzilla
CVE-2014-0163 Openshift: Multiple shell command injection flaws2014-04-03
CVE-2014-0163 — OS Command Injection in Openshift | cvebase