openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with VolumeInUse error. Since the delete operation is retried every 30 seconds for each volume, this could lead to a denial of service attack as the number of API requests being sent to the cloud-provider exceeds the APIs rate-limit.
The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift | Redhat | 3.2.1.23 (including) | 3.2.1.23 (including) |
Openshift | Redhat | 3.3.1.11 (including) | 3.3.1.11 (including) |
Openshift | Redhat | 3.4 (including) | 3.4 (including) |