Bug 1286745 (CVE-2015-7528)

Summary: CVE-2015-7528 OpenShift: pod log location must validate container if provided
Product: [Other] Security Response Reporter: Kurt Seifried <kseifried>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: bleanhar, ccoleman, dmcphers, jialiu, jkeck, jliggitt, jokerman, kseifried, lmeyer, mmccomas, wsun, xtian
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
It was found that OpenShift's API back end did not verify requests for pod log locations, allowing a pod on a Node to request logs for any other pod on that Node. A remote attacker could use this flaw to view sensitive information via pod logs that they would normally not have access to.
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-12-03 19:36:00 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1286747, 1286748    
Bug Blocks: 1286751    

Description Kurt Seifried 2015-11-30 16:12:26 UTC
Jordan Liggitt of Atomic OpenShift reports:

UPSTREAM: 17886: pod log location must validate container if provided #6113 
has security implications, specifically a running pod could make an API call to 
view the logs of any pod running on the same Node.

External references:

https://github.com/openshift/origin/pull/6113

Comment 4 Martin Prpič 2015-12-01 16:38:55 UTC
Acknowledgements:

This issue was discovered by Jordan Liggitt of Red Hat Atomic OpenShift.

Comment 5 errata-xmlrpc 2015-12-03 17:43:04 UTC
This issue has been addressed in the following products:

  RHEL 7 Version of OpenShift Enterprise 3.0
  RHEL 7 Version of OpenShift Enterprise 3.1

Via RHSA-2015:2544 https://access.redhat.com/errata/RHSA-2015:2544

Comment 6 Kurt Seifried 2015-12-03 20:58:16 UTC
*** Bug 1286289 has been marked as a duplicate of this bug. ***

Comment 7 errata-xmlrpc 2015-12-10 20:23:29 UTC
This issue has been addressed in the following products:



Via RHSA-2015:2615 https://rhn.redhat.com/errata/RHSA-2015-2615.html