CVE-2015-7561Missing Authorization in Kubernetes

Severity
3.1LOWNVD
EPSS
0.2%
top 61.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 7
Latest updateAug 20

Description

Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.6 | Impact: 1.4

Affected Packages2 packages

Gok8s.io/kubernetes< 1.2.0-alpha.6

🔴Vulnerability Details

4
OSV
Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes2024-08-20
GHSA
Kubernetes in OpenShift3 Access Control Misconfiguration2022-05-13
OSV
Kubernetes in OpenShift3 Access Control Misconfiguration2022-05-13
CVEList
CVE-2015-7561: Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image2017-08-07

📋Vendor Advisories

1
Red Hat
OpenShift3: Private Docker images can be used by any user, once they are pulled to a node2015-12-15

💬Community

1
Bugzilla
CVE-2015-7561 OpenShift3: Private Docker images can be used by any user, once they are pulled to a node2015-12-16
CVE-2015-7561 — Missing Authorization in Kubernetes | cvebase