Vulnerability Description
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | < 3.10 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2018:2013Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1070Issue Tracking
- https://access.redhat.com/errata/RHSA-2018:2013Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1070Issue Tracking
FAQ
What is CVE-2018-1070?
CVE-2018-1070 is a vulnerability with a CVSS score of 6.5 (MEDIUM). routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulne...
How severe is CVE-2018-1070?
CVE-2018-1070 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1070?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift Container Platform.