Red Hat Security Advisory 2016-0351-01

Discussion in 'News Aggregator' started by Packet Storm, 4 Mar 2016.

  1. Packet Storm

    Packet Storm Guest

    Red Hat Security Advisory 2016-0351-01 - OpenShift Enterprise by Red Hat is the company's cloud computing Platform-as-a-Service solution designed for on-premise or private cloud deployments. An authorization flaw was discovered in Kubernetes; the API server did not properly check user permissions when handling certain requests. An authenticated remote attacker could use this flaw to gain additional access to resources such as RAM and disk space. An authorization flaw was discovered in Kubernetes; the API server did not properly check user permissions when handling certain build configuration strategies. A remote attacker could create build configurations with strategies that violate policy. Although the attacker could not launch the build themselves, if the build configuration files were later launched by other privileged services, user privileges could be bypassed allowing attacker escalation.

    Continue reading...
     

Share This Page

Loading...