CVE-2018-1102 — Improper Input Validation in HAT INC Atomic-openshift
Severity
8.8HIGHNVD
EPSS
1.6%
top 18.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 30
Latest updateMay 13
Description
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages2 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Red Hat▶
source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go↗2018-04-27
💬Community
2Bugzilla▶
CVE-2018-1103 source-to-image: Unsanitized paths in tar.go:ExtractTarStreamFromTarReader() allow malicious containers to overwrite files on the client machine↗2018-04-05
Bugzilla▶
CVE-2018-1102 source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go↗2018-03-29