Red Hat Bugzilla – Bug 1553035
CVE-2018-1070 Routing: Malicous Service configuration can bring down routing for an entire shard.
Last modified: 2018-06-29 18:35:04 EDT
Improper input validation of the Openshift Routing configuration can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
Acknowledgments: Name: Mark Chappell (Red Hat)
This issue affects Openshift Enterprise 3.7.1, and possibly other versions.
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.9 Via RHSA-2018:2013 https://access.redhat.com/errata/RHSA-2018:2013