CVE-2018-10843
—CVSS 3.0
8.8 high
EPSS
1%p70
Published
()
Modified
Description
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.
- Vendors
- redhat
- Products
- openshift container platform
- Weakness
- CWE-20, CWE-732
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.