Back to bug 1316127

Who When What Removed Added
Adam Mariš 2016-03-09 13:29:26 UTC CC security-response-team
Red Hat Bugzilla 2016-03-09 13:29:26 UTC Doc Type --- Bug Fix
Adam Mariš 2016-03-09 13:37:58 UTC Blocks 1316129
Kurt Seifried 2016-03-10 17:18:00 UTC Alias CVE-2016-2160
Kurt Seifried 2016-03-10 17:18:04 UTC Summary EMBARGOED Privilege escalation when changing root password in sti builder image EMBARGOED CVE-2016-2160 Privilege escalation when changing root password in sti builder image
Kurt Seifried 2016-03-10 17:18:07 UTC Whiteboard impact=important,public=no,reported=20160307,source=redhat,cvss2=7.1/AV:N/AC:H/Au:S/C:C/I:C/A:C,openshift-enterprise-3/Security=affected impact=important,public=20160310,reported=20160307,source=redhat,cvss2=7.1/AV:N/AC:H/Au:S/C:C/I:C/A:C,openshift-enterprise-3/Security=affected
Kurt Seifried 2016-03-10 17:18:10 UTC Summary EMBARGOED CVE-2016-2160 Privilege escalation when changing root password in sti builder image CVE-2016-2160 Privilege escalation when changing root password in sti builder image
Kurt Seifried 2016-03-10 17:18:13 UTC Group security, qe_staff
Kurt Seifried 2016-03-10 17:20:54 UTC Depends On 1315187
Kurt Seifried 2016-03-10 17:21:00 UTC Depends On 1315188
Jeremy Choi 2016-03-10 23:35:49 UTC CC jechoi, khong
Kurt Seifried 2016-04-11 22:08:00 UTC Blocks 1326107
Kurt Seifried 2016-05-04 23:40:43 UTC Blocks 1326106
Kurt Seifried 2016-05-05 19:16:14 UTC Doc Text A flaw was found in the building of containers within OpenShift Enterprise. Specifically an attacker could submit an image for building that executes commands within the container as root allowing the attacker to potentially escalate privileges.
Martin Prpič 2016-05-09 16:06:59 UTC Doc Text A flaw was found in the building of containers within OpenShift Enterprise. Specifically an attacker could submit an image for building that executes commands within the container as root allowing the attacker to potentially escalate privileges. A flaw was found in the building of containers within OpenShift Enterprise. An attacker could submit an image for building that executes commands within the container as root, allowing them to potentially escalate privileges.
Kurt Seifried 2016-05-12 16:47:18 UTC Status NEW CLOSED
Resolution --- ERRATA
Last Closed 2016-05-12 12:47:18 UTC
Product Security DevOps Team 2019-09-29 13:45:56 UTC Whiteboard impact=important,public=20160310,reported=20160307,source=redhat,cvss2=7.1/AV:N/AC:H/Au:S/C:C/I:C/A:C,openshift-enterprise-3/Security=affected

Back to bug 1316127