CVE-2018-1070
published 2018-06-12CVE-2018-1070: routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought…
PriorityP434high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
0.86%
54.3th percentile
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | < 3.10 | 3.10 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mfw5-7x4h-m4v5: routing before version 3
ghsa_unreviewed·2022-05-13
CVE-2018-1070 [HIGH] CWE-20 GHSA-mfw5-7x4h-m4v5: routing before version 3
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
Red Hat
Routing: Malicous Service configuration can bring down routing for an entire shard.
vendor_redhat·2018-04-27·CVSS 6.5
CVE-2018-1070 [MEDIUM] CWE-20 Routing: Malicous Service configuration can bring down routing for an entire shard.
Routing: Malicous Service configuration can bring down routing for an entire shard.
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
Improper input validation of the Openshift Routing configuration can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
No detection rules found.
No public exploits indexed.
2018-06-12
Published