CVE Vulnerabilities

CVE-2016-3738

Published: Jun 08, 2016 | Modified: Apr 12, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
6.5 IMPORTANT
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.

Affected Software

NameVendorStart VersionEnd Version
OpenshiftRedhat3.2 (including)3.2 (including)
Red Hat OpenShift Container Platform 3.2RedHatatomic-openshift-0:3.2.0.44-1.git.0.a4463d9.el7*
Red Hat OpenShift Container Platform 3.2RedHatnodejs-node-uuid-0:1.4.7-1.el7*

References