Image Import Configuration Flaw in OpenShift by Red Hat
CVE-2017-15137
4.3MEDIUM
What is CVE-2017-15137?
A configuration issue in OpenShift's image import feature allows unauthorized users to circumvent whitelist restrictions. This flaw can enable users with access to OpenShift to execute commands like 'oc tag' to run images from unauthorized registries. Organizations using OpenShift should assess their configurations and ensure that proper restrictions are enforced to mitigate the risk associated with unauthorized image imports.
Affected Version(s)
atomic-openshift
