cbcvebase.
CVE-2014-0188
published 2014-04-24

CVE-2014-0188: The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user…

PriorityP349high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.67%
74.1th percentile
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

Affected

2 ranges
VendorProductVersion rangeFixed in
redhatopenshift<= 1.2.7
redhatopenshift2.0 – 2.0.5

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.