CVE Vulnerabilities

CVE-2015-8945

Published: Aug 05, 2016 | Modified: Aug 05, 2016
CVSS 3.x
5.1
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 MODERATE
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
5.5 MODERATE
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu

openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the –credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.

Affected Software

Name Vendor Start Version End Version
Origin Openshift * 1.1.6 (including)

References