CVE-2019-10200
published 2021-03-19CVE-2019-10200: A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on…
PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.29%
67.0th percentile
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing management access to AWS resources. With access to the security credentials, the user then has access to the entire infrastructure. Impact to data and system availability is high.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8283-mprv-vc6w: A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workload
ghsa_unreviewed·2022-05-24
CVE-2019-10200 [HIGH] CWE-284 GHSA-8283-mprv-vc6w: A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workload
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing management access to AWS resources. With access to the security credentials, the user then has access to the entire infrastructure. Impact to data and system availability is high.
Red Hat
openshift: Users with permission to schedule pods on master nodes can access credentials for AWS IAM roles
vendor_redhat·2019-07-12·CVSS 7.2
CVE-2019-10200 [HIGH] CWE-284 openshift: Users with permission to schedule pods on master nodes can access credentials for AWS IAM roles
openshift: Users with permission to schedule pods on master nodes can access credentials for AWS IAM roles
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing management access to AWS resources. With access to the security credentials, the user then has access to the entire infrastructure. Impact to data and system availability is high.
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to acc
No detection rules found.
No public exploits indexed.
2021-03-19
Published