CVE-2018-1102
published 2018-04-30CVE-2018-1102: A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in…
PriorityP350high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.42%
82.3th percentile
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | atomic-openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
vendor_redhat·2018-04-27·CVSS 8.8
CVE-2018-1102 [HIGH] CWE-20 source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Statement: Package source-to-image as shipped in Red Hat Software Collections has been rated as Important, because it allows an attacker to get access to the victim's machine, but it requires user interaction.
Mitigation: Customers can turn off the source-to-image (S2I) build strategy to prev
GHSA
GHSA-x9m6-vq2v-79qg: A flaw was found in source-to-image function as shipped with Openshift Enterprise 3
ghsa_unreviewed·2022-05-13
CVE-2018-1102 [HIGH] CWE-20 GHSA-x9m6-vq2v-79qg: A flaw was found in source-to-image function as shipped with Openshift Enterprise 3
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1103 source-to-image: Unsanitized paths in tar.go:ExtractTarStreamFromTarReader() allow malicious containers to overwrite files on the client machine
bugzilla·2018-04-05·CVSS 8.8
CVE-2018-1103 [HIGH] CVE-2018-1103 source-to-image: Unsanitized paths in tar.go:ExtractTarStreamFromTarReader() allow malicious containers to overwrite files on the client machine
CVE-2018-1103 source-to-image: Unsanitized paths in tar.go:ExtractTarStreamFromTarReader() allow malicious containers to overwrite files on the client machine
Openshift Enterprise through version 3.6 has does not properly sanitize archived filenames in source-to-image/pkg/tar/tar.go:ExtractTarStreamFromTarReader(). An attacker can exploit this with a malicous container to overwrite files on client machines when clients use "oc rsync" to connect to that container.
This is a related but separate issue to CVE-2018-1102.
Discussion:
Acknowledgments:
Name: Michael Hanselmann (Independent)
---
Created source-to-image tracking bugs for this issue:
Affects: fedora-all [bug 1590175]
Bugzilla
CVE-2018-1102 source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
bugzilla·2018-03-29·CVSS 8.8
CVE-2018-1102 [HIGH] CVE-2018-1102 source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
CVE-2018-1102 source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go
A flaw was found in source-to-image as shipped with Openshift Enterprise 3.6. A improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Discussion:
The source-to-image (S2I/STI) builder in OpenShift 3.4-3.9 contains a vulnerability allowing an attacker to gain root access on
the host system. The underlying cause is comparable to an issue in Kubernetes' kubectl (and "oc") which was reported publicly on the 25th March 2018 [1].
[1] https://github.com/kubernetes/kubernetes/issues/61297
OpenShift contains similar code as part of its S2I module, specifically in "openshift/source-to-image/pkg/tar/tar.go:ExtractTarStreamFromTarRe
https://access.redhat.com/errata/RHSA-2018:1227https://access.redhat.com/errata/RHSA-2018:1229https://access.redhat.com/errata/RHSA-2018:1231https://access.redhat.com/errata/RHSA-2018:1233https://access.redhat.com/errata/RHSA-2018:1235https://access.redhat.com/errata/RHSA-2018:1237https://access.redhat.com/errata/RHSA-2018:1239https://access.redhat.com/errata/RHSA-2018:1241https://access.redhat.com/errata/RHSA-2018:1243https://access.redhat.com/errata/RHSA-2019:0036https://bugzilla.redhat.com/show_bug.cgi?id=1562246https://access.redhat.com/errata/RHSA-2018:1227https://access.redhat.com/errata/RHSA-2018:1229https://access.redhat.com/errata/RHSA-2018:1231https://access.redhat.com/errata/RHSA-2018:1233https://access.redhat.com/errata/RHSA-2018:1235https://access.redhat.com/errata/RHSA-2018:1237https://access.redhat.com/errata/RHSA-2018:1239https://access.redhat.com/errata/RHSA-2018:1241https://access.redhat.com/errata/RHSA-2018:1243https://access.redhat.com/errata/RHSA-2019:0036https://bugzilla.redhat.com/show_bug.cgi?id=1562246
2018-04-30
Published