CVE-2016-8631Improper Input Validation in RED HAT Openshift Enterprise

Severity
7.7HIGHNVD
CNA6.3
EPSS
0.2%
top 58.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 31
Latest updateMay 13

Description

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:NExploitability: 3.1 | Impact: 4.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-973m-857j-grqw: The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes2022-05-13
CVEList
CVE-2016-8631: The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes2018-07-31

📋Vendor Advisories

1
Red Hat
3: Router sometimes selects new routes over old routes when determining claimed hostnames2016-11-01

💬Community

1
Bugzilla
CVE-2016-8631 OSE 3: Router sometimes selects new routes over old routes when determining claimed hostnames2016-11-01
CVE-2016-8631 — Improper Input Validation in RED | cvebase