Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
References
Link | Resource |
---|---|
https://access.redhat.com/errata/RHSA-2016:1094 | Vendor Advisory |
Configurations
Information
Published : 2016-06-08 10:59
Updated : 2023-02-12 15:20
NVD link : CVE-2016-3738
Mitre link : CVE-2016-3738
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
redhat
- openshift