Red Hat Bugzilla – Bug 1579096
CVE-2018-10843 source-to-image: Builder images with assembler-user LABEL set to root allows attackers to execute arbitrary code
Last modified: 2018-10-15 17:05:21 EDT
OpenShift Container Platform and OpenShift Online have a flaw in the source-to-image functionality. An attacker that can create images with the 'io.openshift.s2i.assemble-user' LABEL set to 'root' can execute arbitrary code with full privileges in the builder pod during S2I build.
Acknowledgments: Name: Jeremy Choi (Red Hat)
This issue has been addressed in the following products: Red Hat OpenShift Container Platform 3.9 Via RHSA-2018:2013 https://access.redhat.com/errata/RHSA-2018:2013