CVE-2017-15138Sensitive Information Exposure in Redhat Openshift Container Platform

Severity
5.0MEDIUMNVD
EPSS
0.2%
top 62.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateMay 13

Description

The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NExploitability: 3.1 | Impact: 1.4

Affected Packages0 packages

Also affects: Openshift Container Platform 3.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qrgj-q9rw-gjrv: The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook2022-05-13
CVEList
CVE-2017-15138: The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook2018-08-13

📋Vendor Advisories

1
Red Hat
atomic-openshift: cluster-reader can escalate to creating builds via webhooks in any project2018-04-11

💬Community

1
Bugzilla
CVE-2017-15138 atomic-openshift: cluster-reader can escalate to creating builds via webhooks in any project2018-04-11
CVE-2017-15138 — Sensitive Information Exposure | cvebase