source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift_container_platform | Redhat | * | 3.7.53 (excluding) |
Openshift_container_platform | Redhat | 3.9 (including) | 3.9 (including) |
Openshift_container_platform | Redhat | 3.9.31 (including) | 3.9.31 (including) |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-0:3.9.31-1.git.0.ef9737b.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-descheduler-0:3.9.13-1.git.267.bb59a3f.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-dockerregistry-0:3.9.31-1.git.351.1bd46ed.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-node-problem-detector-0:3.9.13-1.git.167.5d6b0d4.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | atomic-openshift-web-console-0:3.9.31-1.git.246.bded6a4.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | golang-github-prometheus-node_exporter-0:3.9.31-1.git.890.a55de06.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | mysql-apb-role-0:1.1.11-1.el7 | * |
Red Hat OpenShift Container Platform 3.9 | RedHat | openshift-ansible-0:3.9.31-1.git.34.154617d.el7 | * |