CVE-2015-5274
published 2015-09-18CVE-2015-5274: rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
PriorityP337medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.09%
79.7th percentile
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3fcg-qm7h-hhpw: rubygem-openshift-origin-console in Red Hat OpenShift 2
ghsa_unreviewed·2022-05-17
CVE-2015-5274 [MEDIUM] CWE-77 GHSA-3fcg-qm7h-hhpw: rubygem-openshift-origin-console in Red Hat OpenShift 2
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
Red Hat
2.2: API command injection vulnerability
vendor_redhat·2015-09-16·CVSS 6.5
CVE-2015-5274 [MEDIUM] CWE-20 2.2: API command injection vulnerability
2.2: API command injection vulnerability
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
A command injection flaw was found in the OpenShift Origin Management Console. A remote, authenticated user permitted to send requests to the Broker could use this flaw to execute arbitrary commands with elevated privileges on the Red Hat OpenShift server.
No detection rules found.
No public exploits indexed.
2015-09-18
Published