Bug 1009734 (CVE-2013-4364) - CVE-2013-4364 OpenShift: openshift-origin-broker-util incorrect temporary file usage
Summary: CVE-2013-4364 OpenShift: openshift-origin-broker-util incorrect temporary fil...
Status: CLOSED WONTFIX
Alias: CVE-2013-4364
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard: impact=moderate,public=20140707,repor...
Keywords: Security
Depends On: 1009091 1009736 1009737
Blocks: 1009738
TreeView+ depends on / blocked
 
Reported: 2013-09-19 02:37 UTC by Kurt Seifried
Modified: 2019-06-08 19:43 UTC (History)
14 users (show)

(edit)
Clone Of:
(edit)
Last Closed: 2014-09-06 16:37:40 UTC


Attachments (Terms of Use)

Description Kurt Seifried 2013-09-19 02:37:41 UTC
Michael Scherer of Red Hat reports:

Description of problem:

oo-analytics-export and oo-analytics-import use a predictable filename in /tmp when exporting and importing data.

Comment 4 Kurt Seifried 2014-07-07 19:20:47 UTC
Statement:

On OpenShift Enterprise 2.1 the broker and node should be installed on separate systems, as such there should not be any local untrusted users on the broker system(s). This issue is not currently planned to be addressed in future updates. For additional information, refer to
the Issue Severity Classification:
https://access.redhat.com/security/updates/classification/.


Note You need to log in before you can comment on or make changes to this bug.