CVE-2016-1906
published 2016-02-03CVE-2016-1906: Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
PriorityP354critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.84%
91.0th percentile
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kubernetes | — | — |
| github.com | openshift_origin | >= 0 < 1.1.1 | 1.1.1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Authorization bypass in Openshift in github.com/openshift/origin
osv·2024-08-21
CVE-2016-1906 Authorization bypass in Openshift in github.com/openshift/origin
Authorization bypass in Openshift in github.com/openshift/origin
Authorization bypass in Openshift in github.com/openshift/origin
GHSA
Authorization bypass in Openshift
ghsa·2021-12-20
CVE-2016-1906 [CRITICAL] CWE-285 Authorization bypass in Openshift
Authorization bypass in Openshift
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
OSV
Authorization bypass in Openshift
osv·2021-12-20
CVE-2016-1906 [CRITICAL] Authorization bypass in Openshift
Authorization bypass in Openshift
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
Red Hat
server: build config to a strategy that isn't allowed by policy
vendor_redhat·2016-01-06·CVSS 9.8
CVE-2016-1906 [CRITICAL] CWE-285 server: build config to a strategy that isn't allowed by policy
server: build config to a strategy that isn't allowed by policy
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
An authorization flaw was discovered in Kubernetes; the API server did not properly check user permissions when handling certain build-configuration strategies. A remote attacker could create build configurations with strategies that violate policy. Although the attacker could not launch the build themselves (launch fails when the policy is violated), if the build configuration files were later launched by other privileged services (such as automated triggers), user privileges could be bypassed allowing attacker escalation.
Package: kubernetes (Red Hat Enterprise Linux 7
Debian
CVE-2016-1906: kubernetes - Openshift allows remote attackers to gain privileges by updating a build configu...
vendor_debian·2016·CVSS 9.8
CVE-2016-1906 [CRITICAL] CVE-2016-1906: kubernetes - Openshift allows remote attackers to gain privileges by updating a build configu...
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2016:0070https://access.redhat.com/errata/RHSA-2016:0351https://github.com/openshift/origin/issues/6556https://github.com/openshift/origin/pull/6576https://access.redhat.com/errata/RHSA-2016:0070https://access.redhat.com/errata/RHSA-2016:0351https://github.com/openshift/origin/issues/6556https://github.com/openshift/origin/pull/6576
2016-02-03
Published