LOW3.1
GHSA-2h9c-34v6-3qmr
Kubernetes in OpenShift3 Access Control Misconfiguration
Quick fix
GHSA-2h9c-34v6-3qmr — k8s.io/kubernetes: upgrade to the fixed version with the command below.
go get k8s.io/kubernetes@v1.2.0-alpha.6Details
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/kubernetes
Introduced in:
0Fixed in: 1.2.0-alpha.6Fix
go get k8s.io/kubernetes@v1.2.0-alpha.6References
- https://nvd.nist.gov/vuln/detail/CVE-2015-7561[ADVISORY]
- https://github.com/kubernetes/kubernetes/pull/18909[WEB]
- https://github.com/kubernetes/kubernetes/commit/e185b1028ac8459f7b451e1115399192e96f6ee9[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1291963[WEB]
- https://github.com/kubernetes/kubernetes[PACKAGE]