CVE-2014-3602Sensitive Information Exposure in Redhat Openshift

Severity
2.1LOWNVD
EPSS
0.0%
top 85.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13
Latest updateNov 3

Description

Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages1 packages

NVDredhat/openshift2.1.8+15

🔴Vulnerability Details

2
GHSA
GHSA-7ggv-2g22-cxqr: Red Hat OpenShift Enterprise before 22022-05-13
CVEList
CVE-2014-3602: Red Hat OpenShift Enterprise before 22014-11-13

📋Vendor Advisories

1
Red Hat
OpenShift: /proc/net/tcp information disclosure2014-08-19

🕵️Threat Intelligence

1
Qualys
OpenSSL Vulnerability Recap | Qualys2022-11-03

💬Community

1
Bugzilla
CVE-2014-3602 OpenShift: /proc/net/tcp information disclosure2014-08-19
CVE-2014-3602 — Sensitive Information Exposure | cvebase