source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.
2018-07-02T17:29:00.207
2024-11-21T03:42:07.440
Modified
CVSSv3.0: 8.5 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | openshift_container_platform | < 3.7.53 | Yes |
Application | redhat | openshift_container_platform | 3.9 | Yes |
Application | redhat | openshift_container_platform | 3.9.31 | Yes |