The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
2018-07-16T20:29:00.223
2024-11-21T03:14:08.707
Modified
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | openshift | - | Yes |
Application | redhat | openshift_container_platform | 3.9 | Yes |