5.4
CVSSv2

CVE-2018-1069

Published: 09/03/2018 Updated: 09/10/2019
CVSS v2 Base Score: 5.4 | Impact Score: 6.4 | Exploitability Score: 5.5
CVSS v3 Base Score: 7.1 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 481
Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 3.7

Vendor Advisories

GlusterFS and NFS network filesystems rely on File System User ID and Group ID information in order to restrict access to file shares However, it's possible to overwrite the Openshift restrictions on container UserId and GroupdId as they are not validated before being sent over the Openshift Network An attacker could use the flaw to read and writ ...