7.5
CVSSv2

CVE-2014-3674

Published: 13/11/2014 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Red Hat OpenShift Enterprise prior to 2.2 does not properly restrict access to gears, which allows remote malicious users to access the network resources of arbitrary gears via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 2.1.2

redhat openshift 2.0.6

redhat openshift 2.1.5

redhat openshift 2.1

redhat openshift 2.0.5

redhat openshift 2.0.2

redhat openshift 2.1.1

redhat openshift 2.0.1

redhat openshift

redhat openshift 2.1.7

redhat openshift 2.1.4

redhat openshift 2.0.3

redhat openshift 2.1.3

redhat openshift 2.0.4

redhat openshift 2.1.6

redhat openshift 2.0

Vendor Advisories

It was found that OpenShift Enterprise 21 did not properly restrict access to services running on different gears This could allow an attacker to access unprotected network resources running in another user's gear ...