CVE-2016-8651
published 2018-08-01CVE-2016-8651: An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull…
PriorityP414low3.5CVSS 3.0
AVAACLPRLUINSUCLINAN
EPSS
1.35%
68.4th percentile
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | openshift_enterprise | — | — |
| redhat | openshift | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.03.5LOWCVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.7LOWAV:A/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8x5v-7r3g-jgfj: An input validation flaw was found in the way OpenShift 3 handles requests for images
ghsa_unreviewed·2022-05-13
CVE-2016-8651 [LOW] CWE-20 GHSA-8x5v-7r3g-jgfj: An input validation flaw was found in the way OpenShift 3 handles requests for images
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
Red Hat
3: Pulling of any image is possible with it manifest
vendor_redhat·2016-12-07·CVSS 3.1
CVE-2016-8651 [LOW] CWE-20 3: Pulling of any image is possible with it manifest
3: Pulling of any image is possible with it manifest
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
An input validation flaw was found in the way OpenShift handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8651 OpenShift Enterprise 3: Pulling of any image is possible with it manifest
bugzilla·2016-11-23·CVSS 3.1
CVE-2016-8651 [LOW] CVE-2016-8651 OpenShift Enterprise 3: Pulling of any image is possible with it manifest
CVE-2016-8651 OpenShift Enterprise 3: Pulling of any image is possible with it manifest
It is reported that given the manifest data for a container that is not owned by a user that user will still be able to pull the container and access the contents of it.
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Red Hat OpenShift Enterprise 3.2
Red Hat OpenShift Container Platform 3.3
Via RHSA-2016:2915 https://access.redhat.com/errata/RHSA-2016:2915
Qualys
Update: Last Adobe 0-day Patched for the Year | Qualys
blogs_qualys·2015-12-28·CVSS 8.8
CVE-2015-8651 [HIGH] Update: Last Adobe 0-day Patched for the Year | Qualys
Update : Qualys QID is 124421: Adobe Flash Player and AIR Security Update (APSB16-01).
Original : Adobe issued today their last update for 2015 for its Flash player. It addresses nineteen vulnerabilities and was released out of band because one of them (CVE-2015-8651) is under attack in the wild. At this point attacks are limited to special targets. The update is numbered APSB16-01 , not APSB15-33 as expected, most likely because it is basically the planned January 2016 update, anticipated due to the circumstances.
As with all 0-days fixes this one deserves special attention and a quick turnaround.
## Related content
Qualys
Update: Last Adobe 0-day Patched for the Year | Qualys
blogs_qualys·2015-12-28·CVSS 8.8
CVE-2015-8651 [HIGH] Update: Last Adobe 0-day Patched for the Year | Qualys
Update: Qualys QID is 124421: Adobe Flash Player and AIR Security Update (APSB16-01).
Original: Adobe issued today their last update for 2015 for its Flash player. It addresses nineteen vulnerabilities and was released out of band because one of them (CVE-2015-8651) is under attack in the wild. At this point attacks are limited to special targets. The update is numbered APSB16-01, not APSB15-33 as expected, most likely because it is basically the planned January 2016 update, anticipated due to the circumstances.
As with all 0-days fixes this one deserves special attention and a quick turnaround.
### Related
2018-08-01
Published