8.8
CVSSv3

CVE-2018-1102

Published: 30/04/2018 Updated: 12/02/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift 3.1

redhat openshift 3.0

redhat openshift 3.2

redhat openshift 3.7

redhat openshift 3.3

redhat openshift 3.4

redhat openshift 3.5

redhat openshift 3.6

redhat openshift 3.9

redhat openshift 3.8

Vendor Advisories

Synopsis Critical: OpenShift Container Platform 35 security, bug fix, and enhancement update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 35Red Hat Product Security has rated this update as having a security impact of Critical A Comm ...
Synopsis Critical: OpenShift Container Platform 36 security and bug fix update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 36Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerabili ...
Synopsis Critical: OpenShift Container Platform 37 security and bug fix update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 37Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerabili ...
Synopsis Critical: OpenShift Container Platform 33 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 33Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring S ...
Synopsis Critical: OpenShift Container Platform 39 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 39Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring S ...
Synopsis Critical: OpenShift Container Platform 32 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 32Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring S ...
Synopsis Critical: OpenShift Container Platform 31 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 31Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring S ...
Synopsis Critical: OpenShift Container Platform 38 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 38Red Hat Product Security has rated this update as having a security impactof Critical A Common Vulnerability Scoring Sy ...
Synopsis Critical: OpenShift Container Platform 34 security update Type/Severity Security Advisory: Critical Topic An update is now available for Red Hat OpenShift Container Platform 34Red Hat Product Security has rated this update as having a security impact of Critical A Common Vulnerability Scoring S ...
Synopsis Important: source-to-image security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for source-to-image is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vul ...
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3x An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/targo leads to privilege escalation ...