Red Hat Bugzilla – Bug 1397987
CVE-2016-8651 OpenShift Enterprise 3: Pulling of any image is possible with it manifest
Last modified: 2016-12-14 12:00:21 EST
It is reported that given the manifest data for a container that is not owned by a user that user will still be able to pull the container and access the contents of it.
This issue has been addressed in the following products: Red Hat OpenShift Enterprise 3.1 Red Hat OpenShift Enterprise 3.2 Red Hat OpenShift Container Platform 3.3 Via RHSA-2016:2915 https://access.redhat.com/errata/RHSA-2016:2915