|
|
Subscribe / Log in / New account

atomic-openshift: information leak

Package(s):atomic-openshift CVE #(s):CVE-2016-5392
Created:July 15, 2016 Updated:July 20, 2016
Description:

From the Red Hat advisory:

The Kubernetes API server contains a watch cache that speeds up performance. Due to an input validation error OpenShift Enterprise may return data for other users and projects when queried by a user. An attacker with knowledge of other project names could use this vulnerability to view their information.

Alerts:
Red Hat RHSA-2016:1427-01 atomic-openshift 2016-07-14

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds