CVE-2016-2160Redhat Openshift vulnerability

CWE-2644 documents4 sources
Severity
8.8HIGHNVD
EPSS
1.2%
top 21.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 8

Description

Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

1
CVEList
CVE-2016-2160: Red Hat OpenShift Enterprise 32016-06-08

📋Vendor Advisories

1
Red Hat
Privilege escalation when changing root password in sti builder image2016-03-10

💬Community

1
Bugzilla
CVE-2016-2160 Privilege escalation when changing root password in sti builder image2016-03-09
CVE-2016-2160 — Redhat Openshift vulnerability | cvebase