CVE-2015-5222
published 2015-08-24CVE-2015-5222: Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary…
PriorityP348high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
2.69%
84.2th percentile
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | — | — |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x7xw-w98q-fgfm: Red Hat OpenShift Enterprise 3
ghsa_unreviewed·2022-05-17
CVE-2015-5222 [HIGH] GHSA-x7xw-w98q-fgfm: Red Hat OpenShift Enterprise 3
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.
Red Hat
OpenShift3: Exec operations should be forbidden to privileged pods such as builder pods
vendor_redhat·2015-08-19·CVSS 8.5
CVE-2015-5222 [HIGH] CWE-862 OpenShift3: Exec operations should be forbidden to privileged pods such as builder pods
OpenShift3: Exec operations should be forbidden to privileged pods such as builder pods
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.
An improper permission check issue was discovered in the server admission control component in OpenShift. A user with build permissions could use this flaw to execute arbitrary shell commands on a build pod with the privileges of the root user.
Suricata
ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)
suricata·2015-03-11·CVSS 4.3
CVE-2015-0204 [MEDIUM] ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)
ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)
Rule: alert tcp any [21,25,110,143,443,465,587,636,989:995,5061,5222] -> $HOME_NET any (msg:"ET EXPLOIT FREAK Weak Export Suite From Server (CVE-2015-0204)"; flow:established,to_client; content:"|16 03|"; depth:2; byte_test:1,<,4,0,relative; content:"|02|"; distance:3; within:1; byte_jump:1,37,relative; content:"|00 19|"; within:2; fast_pattern; threshold:type limit,track by_dst,count 1,seconds 1200; reference:url,blog.cryptographyengineering.com/2015/03/attack-of-week-freak-or-factoring-nsa.html; reference:cve,2015-0204; reference:cve,2015-1637; classtype:bad-unknown; sid:2020661; rev:4; metadata:created_at 2015_03_11, cve CVE_2015_0204, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_
2015-08-24
Published