CVE-2014-3602
published 2014-11-13CVE-2014-3602: Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
30.4th percentile
Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | <= 2.1.8 | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenShift: /proc/net/tcp information disclosure
vendor_redhat·2014-08-19·CVSS 2.1
CVE-2014-3602 [LOW] CWE-200 OpenShift: /proc/net/tcp information disclosure
OpenShift: /proc/net/tcp information disclosure
Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.
It was found that OpenShift Enterprise did not restrict access to the /proc/net/tcp file in gears, which allowed local users to view all listening connections and connected sockets. This could result in remote system's IP or port numbers in use to be exposed, which may be useful for further targeted attacks.
Package: Security (OpenShift Enterprise 1) - Will not fix
GHSA
GHSA-7ggv-2g22-cxqr: Red Hat OpenShift Enterprise before 2
ghsa_unreviewed·2022-05-13
CVE-2014-3602 [LOW] GHSA-7ggv-2g22-cxqr: Red Hat OpenShift Enterprise before 2
Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3602 OpenShift: /proc/net/tcp information disclosure
bugzilla·2014-08-19·CVSS 2.1
CVE-2014-3602 [LOW] CVE-2014-3602 OpenShift: /proc/net/tcp information disclosure
CVE-2014-3602 OpenShift: /proc/net/tcp information disclosure
OpenShift fails to restrict access to /proc/net/tcp which allows local users
to view all listening connections and connected sockets. This can result in
remote systems IP/port numbers in use being exposed which may be useful for
further targeted attacks. Please note that for local listeners OpenShift
restricts connections to within the cartridge by default, so even with the
knowledge of the local port and ip the attacker will not be able to connect.
Discussion:
*** Bug 817596 has been marked as a duplicate of this bug. ***
---
*** Bug 1147598 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
RHEL 6 Version of OpenShift Enterprise 2.2
Via RHSA-2014:1796 https://r
Qualys
OpenSSL Vulnerability Recap | Qualys
blogs_qualys·2022-11-03·CVSS 7.5
[HIGH] OpenSSL Vulnerability Recap | Qualys
#### Table of Contents
- Knowing more about the vulnerability allows us to dissect why it is not as industry-changing as Heartbleed was 8 years ago.
- Related Posts
Last week a CRITICAL vulnerability in OpenSSL was pre-announced to give organizations a head start in coming up with a playbook for how to address the highest severity OpenSSL vulnerability since Heartbleed in 2014. A lot of effort was put in by vendors and organizations alike to come up with a proper response, while eagerly awaiting the announcement on November 1. When the information was released, the vulnerability was downgraded in severity and split into two (2) CVEs (CVE-2022-37786 and CVE-2022-3602), decreasing the impact on products that leverage OpenSSL 3.x. These two (2) OpenSSL vulnerabilities have been addressed in
2014-11-13
Published