CVE-2018-1102
Find out more about CVE-2018-1102 from the MITRE CVE dictionary dictionary and NIST NVD.
CVSS v3 metrics
| CVSS3 Base Score | 9.9 |
|---|---|
| CVSS3 Base Metrics | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low |
| User Interaction | None |
| Scope | Changed |
| Confidentiality | High |
| Integrity Impact | High |
| Availability Impact | High |
Red Hat Security Errata
| Platform | Errata | Release Date |
|---|---|---|
| Red Hat OpenShift Container Platform 3.5 (atomic-openshift) | RHSA-2018:1235 | 2018-04-30 |
| Red Hat OpenShift Container Platform 3.4 (atomic-openshift) | RHSA-2018:1237 | 2018-04-30 |
| Red Hat OpenShift Container Platform 3.6 (atomic-openshift) | RHSA-2018:1233 | 2018-04-30 |
| Red Hat OpenShift Container Platform 3.2 (atomic-openshift) | RHSA-2018:1241 | 2018-04-29 |
| Red Hat OpenShift Enterprise 3.1 (atomic-openshift) | RHSA-2018:1243 | 2018-04-29 |
| Red Hat OpenShift Container Platform 3.8 (atomic-openshift) | RHSA-2018:1229 | 2018-04-28 |
| Red Hat OpenShift Container Platform 3.9 (atomic-openshift) | RHSA-2018:1227 | 2018-04-28 |
| Red Hat OpenShift Container Platform 3.3 (atomic-openshift) | RHSA-2018:1239 | 2018-04-29 |
| Red Hat OpenShift Container Platform 3.7 (atomic-openshift) | RHSA-2018:1231 | 2018-04-29 |
Acknowledgements
Red Hat は、この問題をご報告いただいた Michael Hanselmann 氏 (hansmi.ch) に謝意を表します。Mitigation
source-to-image (S2I) ビルドストラテジー を無効にすると、悪用可能な機能へのアクセスを防ぐことができます。S2I ビルドストラテジーを無効にする方法については、以下の製品ドキュメントを参照してください。
* Disabling S2I in OpenShift Enterprise 3.0 - https://docs.openshift.com/enterprise/3.0/admin_guide/securing_builds.html#disabling-a-build-strategy-globally
* Disabling S2I in OpenShift Enterprise 3.1 - https://docs.openshift.com/enterprise/3.1/admin_guide/securing_builds.html#disabling-a-build-strategy-globally
* Disabling S2I in OpenShift Enterprise 3.2 - https://docs.openshift.com/enterprise/3.2/admin_guide/securing_builds.html#disabling-a-build-strategy-globally
* Disabling S2I in OpenShift Enterprise 3.3 - https://access.redhat.com/documentation/en-us/openshift_container_platform/3.3/html/cluster_administration/admin-guide-securing-builds
* Disabling S2I in OpenShift Enterprise 3.4 - https://access.redhat.com/documentation/en-us/openshift_container_platform/3.4/html/cluster_administration/admin-guide-securing-builds
* Disabling S2I in OpenShift Enterprise 3.5 - https://access.redhat.com/documentation/en-us/openshift_container_platform/3.5/html/cluster_administration/admin-guide-securing-builds
* Disabling S2I in OpenShift Enterprise 3.6 - https://access.redhat.com/documentation/en-us/openshift_container_platform/3.6/html/cluster_administration/admin-guide-securing-builds
* Disabling S2I in OpenShift Enterprise 3.7 - https://access.redhat.com/documentation/en-us/openshift_container_platform/3.7/html/cluster_administration/admin-guide-securing-builds
* OpenShift Enterprise 3.8 is not a production version (only for upgrades).
* Disabling S2I in OpenShift Enterprise 3.9 - https://access.redhat.com/documentation/en-us/openshift_container_platform/3.9/html/cluster_administration/admin-guide-securing-builds
