10
CVSSv2

CVE-2016-1906

Published: 03/02/2016 Updated: 13/02/2023
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Openshift allows remote malicious users to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kubernetes kubernetes -

Vendor Advisories

An authorization flaw was discovered in Kubernetes; the API server did not properly check user permissions when handling certain build-configuration strategies A remote attacker could create build configurations with strategies that violate policy Although the attacker could not launch the build themselves (launch fails when the policy is violate ...