Bug 1331229 (CVE-2016-3708)
Summary: | CVE-2016-3708 OpenShiftEnterprise 3: s2i builds implicitly perform docker builds | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Kurt Seifried <kseifried> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | bleanhar, ccoleman, dmcphers, jialiu, jkeck, jokerman, kseifried, lmeyer, mmccomas |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: |
A flaw was found in OpenShift Enterprise when multi-tenant SDN is enabled and a build is run within a namespace that would normally be isolated from pods in other namespaces. If an s2i build is run in such an environment the container being built can access network resources on pods that should not be available to it.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2016-05-20 00:21:20 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1330735 | ||
Bug Blocks: | 1331230, 1335624 |
Description
Kurt Seifried
2016-04-28 04:11:59 UTC
Acknowledgments: Name: Ben Parees (Red Hat) This is an issue only when multi-tenant SDN is enabled and the build is run in a namespace that would normally be isolated from pods in other namespaces. The pod can access normal network functions as if the multitenant SDN was not enabled (equivalent to when the standard SDN function is enabled). This is an issue only when multi-tenant SDN is enabled and the build is run in a namespace that would normally be isolated from pods in other namespaces. The pod can access normal network functions as if the multitenant SDN was not enabled (equivalent to when the standard SDN function is enabled). This issue has been addressed in the following products: Red Hat OpenShift Enterprise 3.2 Via RHSA-2016:1094 https://access.redhat.com/errata/RHSA-2016:1094 |