Access Control Vulnerability in Red Hat OpenShift Enterprise Affecting Network Filesystems
CVE-2018-1069

7.1HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
9 March 2018

What is CVE-2018-1069?

An access control vulnerability exists in Red Hat OpenShift Enterprise 3.7, allowing attackers to modify the UserId and GroupId settings for GlusterFS and NFS filesystems. This weakness can lead to unauthorized access, enabling malicious actors to read and write to any data within the network filesystem, posing significant risks to data integrity and confidentiality.

Affected Version(s)

OpenShift Enterprise 3.7

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-1069 : Access Control Vulnerability in Red Hat OpenShift Enterprise Affecting Network Filesystems