Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1579096 - (CVE-2018-10843) CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set to root allows attackers to execute arbitrary code
CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set ...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
impact=important,public=20180524,repo...
: Security
Depends On: 1582976 1582977 1583421
Blocks: 1579098
  Show dependency treegraph
 
Reported: 2018-05-16 20:22 EDT by Sam Fowler
Modified: 2018-10-15 17:05 EDT (History)
19 users (show)

See Also:
Fixed In Version: atomic-openshift 3.7.53, atomic-openshift 3.9.31
Doc Type: If docs needed, set a value
Doc Text:
A privilege escalation flaw was found in the source-to-image component of Openshift Container Platform which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:2013 None None None 2018-06-27 14:01 EDT

  None (edit)
Description Sam Fowler 2018-05-16 20:22:38 EDT
OpenShift Container Platform and OpenShift Online have a flaw in the source-to-image functionality. An attacker that can create images with the 'io.openshift.s2i.assemble-user' LABEL set to 'root' can execute arbitrary code with full privileges in the builder pod during S2I build.
Comment 6 Jason Shepherd 2018-05-27 23:54:07 EDT
Acknowledgments:

Name: Jeremy Choi (Red Hat)
Comment 10 errata-xmlrpc 2018-06-27 14:01:17 EDT
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 3.9

Via RHSA-2018:2013 https://access.redhat.com/errata/RHSA-2018:2013

Note You need to log in before you can comment on or make changes to this bug.