CVE-2018-14632
published 2018-09-06CVE-2018-14632: An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker…
PriorityP336high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
EPSS
1.95%
78.1th percentile
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | evanphx_json-patch | >= 0 < 0.5.2 | 0.5.2 |
| github.com | evanphx_json-patch | >= 3.0.0 < 3.0.1-0.20180525145409-4c9aadca8f89 | 3.0.1-0.20180525145409-4c9aadca8f89 |
| github.com | evanphx_json-patch | >= 3.0.0+incompatible < 3.0.1-0.20180525145409-4c9aadca8f89+incompatible | 3.0.1-0.20180525145409-4c9aadca8f89+incompatible |
| red_hat | atomic-openshift | — | — |
| redhat | openshift_container_platform | <= 3.7 | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv3.07.7HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
atomic-openshift: oc patch with json causes masterapi service crash
vendor_redhat·2018-09-06·CVSS 7.7
CVE-2018-14632 [HIGH] CWE-787 atomic-openshift: oc patch with json causes masterapi service crash
atomic-openshift: oc patch with json causes masterapi service crash
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
An out of bounds write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform 3.x. An attacker can use this flaw to cause a denial of service attack on the Openshift master API service which provides cluster management.
Statement: A multi-master Openshift Container Platform cluster is more resilient, however a sustained attack would still have an important impact.
Package: atomic-openshi
GHSA
JSON-Patch Out-of-bounds Write vulnerability
ghsa·2022-05-13
CVE-2018-14632 [HIGH] CWE-787 JSON-Patch Out-of-bounds Write vulnerability
JSON-Patch Out-of-bounds Write vulnerability
An out of bound write can occur when patching an Openshift object using the `oc patch` functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
OSV
JSON-Patch Out-of-bounds Write vulnerability
osv·2022-05-13
CVE-2018-14632 [HIGH] JSON-Patch Out-of-bounds Write vulnerability
JSON-Patch Out-of-bounds Write vulnerability
An out of bound write can occur when patching an Openshift object using the `oc patch` functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
OSV
Out-of-bounds write in github.com/evanphx/json-patch
osv·2021-04-14
CVE-2018-14632 Out-of-bounds write in github.com/evanphx/json-patch
Out-of-bounds write in github.com/evanphx/json-patch
A malicious JSON patch can cause a panic due to an out-of-bounds write attempt. This can be used as a denial of service vector if exposed to arbitrary user input.
OSV
CVE-2018-14632: An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3
osv·2018-09-06·CVSS 7.7
CVE-2018-14632 [HIGH] CVE-2018-14632: An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHBA-2018:2652https://access.redhat.com/errata/RHSA-2018:2654https://access.redhat.com/errata/RHSA-2018:2709https://access.redhat.com/errata/RHSA-2018:2906https://access.redhat.com/errata/RHSA-2018:2908https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03#diff-65c563bba473be9d94ce4d033f74810ehttps://access.redhat.com/errata/RHBA-2018:2652https://access.redhat.com/errata/RHSA-2018:2654https://access.redhat.com/errata/RHSA-2018:2709https://access.redhat.com/errata/RHSA-2018:2906https://access.redhat.com/errata/RHSA-2018:2908https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03#diff-65c563bba473be9d94ce4d033f74810e
2018-09-06
Published