Bug 1148170 (CVE-2014-3674)

Summary: CVE-2014-3674 OpenShift Enterprise: gears fail to properly isolate network traffic
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: anli, bleanhar, ccoleman, dmcphers, jdetiber, jialiu, jkeck, jokerman, kseifried, lmeyer, mmccomas, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
It was found that OpenShift Enterprise 2.1 did not properly restrict access to services running on different gears. This could allow an attacker to access unprotected network resources running in another user's gear.
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-06-10 20:24:55 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1147598, 1148173    
Bug Blocks: 1148171    

Description Kurt Seifried 2014-09-30 20:28:07 UTC
It was reported that OpenShift Enterprise fails to properly restrict access to 
network resources between different gears. This could allow an attacker to 
access an unprotected network resource running in another users gear.

Comment 3 Anping Li 2014-11-03 06:46:44 UTC
Verified and pass on OSE-2.2
oo-gear-firewall was kick off to fix the security issue.
For new installation, new security rules have been enabled.
For exist instance, oo-gear-firewall should be run to fix the security issue

Comment 4 errata-xmlrpc 2014-11-03 19:55:12 UTC
This issue has been addressed in the following products:

  RHEL 6 Version of OpenShift Enterprise 2.2

Via RHSA-2014:1796 https://rhn.redhat.com/errata/RHSA-2014-1796.html

Comment 6 Martin Prpič 2014-11-19 10:27:27 UTC
IssueDescription:

It was found that OpenShift Enterprise 2.1 did not properly restrict access to services running on different gears. This could allow an attacker to access unprotected network resources running in another user's gear.

Comment 7 errata-xmlrpc 2014-11-25 18:19:40 UTC
This issue has been addressed in the following products:

  RHEL 6 Version of OpenShift Enterprise 2.1

Via RHSA-2014:1906 https://rhn.redhat.com/errata/RHSA-2014-1906.html