CVE-2018-1070

Impact:
Important
Public Date:
2018-04-27
CWE:
CWE-20
Bugzilla:
1553035: CVE-2018-1070 Routing: Malicous Service configuration can bring down routing for an entire shard.
Improper input validation of the Openshift Routing configuration can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.

Find out more about CVE-2018-1070 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Changed
Confidentiality None
Integrity Impact None
Availability Impact High

Red Hat Security Errata

Platform Errata Release Date
Red Hat OpenShift Container Platform 3.9 RHSA-2018:2013 2018-06-27

Acknowledgements

This issue was discovered by Mark Chappell (Red Hat).
Last Modified