CVE-2016-1906Improper Authorization in Openshift Origin

Severity
9.8CRITICALNVD
EPSS
2.5%
top 14.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 3
Latest updateAug 21

Description

Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
Authorization bypass in Openshift in github.com/openshift/origin2024-08-21
GHSA
Authorization bypass in Openshift2021-12-20
OSV
Authorization bypass in Openshift2021-12-20

📋Vendor Advisories

2
Red Hat
server: build config to a strategy that isn't allowed by policy2016-01-06
Debian
CVE-2016-1906: kubernetes - Openshift allows remote attackers to gain privileges by updating a build configu...2016

💬Community

1
Bugzilla
CVE-2016-1906 Kubernetes api server: build config to a strategy that isn't allowed by policy2016-01-12