CVE-2018-14632: High severity red hat openshift container platform vulnerability
A out of bound write can occur when patching a Openshift object using the 'oc patch' functionality in OpenShift Container Platform 3.6 and earlier. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
Other sources
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
An out of bounds write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform 3.x. An attacker can use this flaw to cause a denial of service attack on the Openshift master API service which provides cluster management.
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-14632?
CVE-2018-14632 is classified as a medium severity vulnerability that can lead to denial of service.
How do I fix CVE-2018-14632?
To mitigate CVE-2018-14632, upgrade to atomic-openshift versions 3.6.173.0.130-1.git.0.8d78a39.el7, 3.7.72-1.git.0.925b9cd.el7, 3.9.51-1.git.0.dc3a40b.el7, or 3.10.0-1.git.0.91d1e89.el7.
What systems are affected by CVE-2018-14632?
CVE-2018-14632 affects OpenShift Container Platform versions 3.6 and earlier.
Can CVE-2018-14632 be exploited remotely?
Yes, an attacker can exploit CVE-2018-14632 remotely to cause a denial of service.
What is the nature of the vulnerability in CVE-2018-14632?
CVE-2018-14632 is an out-of-bounds write vulnerability during the patching of OpenShift objects.