CVE-2018-17456

Impact:
Important
Public Date:
2018-10-05
CWE:
CWE-77
Bugzilla:
1636619: CVE-2018-17456 git: arbitrary code execution via .gitmodules

The MITRE CVE dictionary describes this issue as:

Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.

Find out more about CVE-2018-17456 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

OpenShift Container Platform (OCP) source-to-image uses the git client packaged with the OCP container images. Since RHEL7 and its associated images are impacted, source-to-image is also impacted. The atomic-openshift package running on the masters controls the code that determines the source-to-image build image in use, therefore a cluster update is required to patch this issue. Full instructions will be provided in Security Errata provided for this issue.

In OCP 3.6 and earlier, source-to-image executes in a privileged container on the node. Therefore the severity of this CVE is important for these versions. OCP 3.7 and later execute source-to-image git pulls in an unprivileged init container.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 8.8
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact High

Affected Packages State

Platform Package State
Red Hat Software Collections for Red Hat Enterprise Linux rh-git29-git Affected
Red Hat Software Collections for Red Hat Enterprise Linux rh-git218-git Affected
Red Hat OpenShift Enterprise 3.2 source-to-image Affected
Red Hat OpenShift Enterprise 3.1 source-to-image Affected
Red Hat OpenShift Enterprise 3.0 source-to-image Affected
Red Hat OpenShift Container Platform 3.9 source-to-image Affected
Red Hat OpenShift Container Platform 3.7 source-to-image Affected
Red Hat OpenShift Container Platform 3.6 source-to-image Affected
Red Hat OpenShift Container Platform 3.5 source-to-image Affected
Red Hat OpenShift Container Platform 3.4 source-to-image Affected
Red Hat OpenShift Container Platform 3.3 source-to-image Affected
Red Hat Mobile Application Platform On-Premise 4 fh-scm Not affected
Red Hat JBoss Fuse 7 camel Under investigation
Red Hat JBoss Fuse 6 camel Under investigation
Red Hat Enterprise Linux 7 git Affected
Red Hat Enterprise Linux 6 git Will not fix

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.