It was reported that OpenShift Enterprise fails to properly restrict access to network resources between different gears. This could allow an attacker to access an unprotected network resource running in another users gear.
Verified and pass on OSE-2.2 oo-gear-firewall was kick off to fix the security issue. For new installation, new security rules have been enabled. For exist instance, oo-gear-firewall should be run to fix the security issue
This issue has been addressed in the following products: RHEL 6 Version of OpenShift Enterprise 2.2 Via RHSA-2014:1796 https://rhn.redhat.com/errata/RHSA-2014-1796.html
IssueDescription: It was found that OpenShift Enterprise 2.1 did not properly restrict access to services running on different gears. This could allow an attacker to access unprotected network resources running in another user's gear.
This issue has been addressed in the following products: RHEL 6 Version of OpenShift Enterprise 2.1 Via RHSA-2014:1906 https://rhn.redhat.com/errata/RHSA-2014-1906.html