Vulnerability Description
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | <= 3.7 |
| Starcounter-Jack | Json-Patch | - |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHBA-2018:2652Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2654Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2709Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2906Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2908Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632Issue TrackingPatchVendor Advisory
- https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81PatchThird Party Advisory
- https://access.redhat.com/errata/RHBA-2018:2652Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2654Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2709Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2906Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2908Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632Issue TrackingPatchVendor Advisory
- https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81PatchThird Party Advisory
FAQ
What is CVE-2018-14632?
CVE-2018-14632 is a vulnerability with a CVSS score of 7.7 (HIGH). An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of serv...
How severe is CVE-2018-14632?
CVE-2018-14632 has been rated HIGH with a CVSS base score of 7.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-14632?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift Container Platform, Starcounter-Jack Json-Patch.