CVE-2018-1069
published 2018-03-09CVE-2018-1069: Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and…
PriorityP432high7.1CVSS 3.0
AVAACHPRLUINSUCHIHAH
EPSS
0.59%
44.6th percentile
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | openshift_enterprise | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h362-mrg5-244p: Red Hat OpenShift Enterprise version 3
ghsa_unreviewed·2022-05-13
CVE-2018-1069 [HIGH] CWE-732 GHSA-h362-mrg5-244p: Red Hat OpenShift Enterprise version 3
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.
Red Hat
Networking: container networking does not prevent access to network resources
vendor_redhat·2018-03-08·CVSS 7.1
CVE-2018-1069 [HIGH] CWE-20 Networking: container networking does not prevent access to network resources
Networking: container networking does not prevent access to network resources
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.
GlusterFS and NFS network filesystems rely on File System User ID and Group ID information in order to restrict access to file shares. However, it's possible to overwrite the Openshift restrictions on container UserId and GroupdId as they are not validated before being sent over the Openshift Network. An attacker could use the flaw to read and write any data on the network filesystem.
Mitigation: If exposing shares with NFS or GlusterFS to Openshift Nodes use EgressNetwor
No detection rules found.
No public exploits indexed.
2018-03-09
Published