LOW · 3.1

CVE-2016-8651

An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access t...

Vulnerability Description

An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.

CVSS Score

3.1

LOW

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RedhatOpenshift3.0
RedhatOpenshift Container Platform3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-8651?

CVE-2016-8651 is a vulnerability with a CVSS score of 3.1 (LOW). An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access t...

How severe is CVE-2016-8651?

CVE-2016-8651 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-8651?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift, Redhat Openshift Container Platform.