cbcvebase.
CVE-2018-14632
published 2018-09-06

CVE-2018-14632: An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker…

PriorityP336high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
EPSS
1.95%
78.1th percentile
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

Affected

8 ranges
VendorProductVersion rangeFixed in
github.comevanphx_json-patch>= 0 < 0.5.20.5.2
github.comevanphx_json-patch>= 3.0.0 < 3.0.1-0.20180525145409-4c9aadca8f893.0.1-0.20180525145409-4c9aadca8f89
github.comevanphx_json-patch>= 3.0.0+incompatible < 3.0.1-0.20180525145409-4c9aadca8f89+incompatible3.0.1-0.20180525145409-4c9aadca8f89+incompatible
red_hatatomic-openshift
redhatopenshift_container_platform<= 3.7
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv3.07.7HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
osv7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.