CVE-2017-15137
published 2018-07-16CVE-2017-15137: The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with…
PriorityP426medium5.3CVSS 3.0
AVNACLPRNUINSUCNILAN
EPSS
0.99%
58.9th percentile
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag
vendor_redhat·2018-03-28·CVSS 4.3
CVE-2017-15137 [MEDIUM] CWE-20 atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag
atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.10) - Not affected
Package: atomic-openshift (Red Hat OpenShift Container Platform 3.7) - Affected
GHSA
GHSA-fcgm-gwv3-mqcg: The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example
ghsa_unreviewed·2022-05-13
CVE-2017-15137 [MEDIUM] CWE-20 GHSA-fcgm-gwv3-mqcg: The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
No detection rules found.
No public exploits indexed.
2018-07-16
Published