Vulnerability Description
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each volume, this could lead to a denial of service attack as the number of API requests being sent to the cloud-provider exceeds the API's rate-limit.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | 3.2.1.23 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94991Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9592Issue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/94991Third Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9592Issue TrackingThird Party Advisory
FAQ
What is CVE-2016-9592?
CVE-2016-9592 is a vulnerability with a CVSS score of 4.3 (MEDIUM). openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation ...
How severe is CVE-2016-9592?
CVE-2016-9592 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9592?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift.