Red Hat Bugzilla – Bug 1597090
CVE-2018-10885 atomic-openshift: Malicious network-policy can cause Openshift Routing DoS when using ovs-networkpolicy plugin
Last modified: 2018-08-01 07:29:55 EDT
A malicious network-policy configuration can cause Openshift Routing to crash when using ovs-network policy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9 Cluster.
The ovs-networkpolicy plugin was tech preview until the 3.7 release, ref: https://docs.openshift.com/container-platform/3.6/install_config/configuring_sdn.html
Acknowledgments: Name: Taichi Kageyama (NEC)
Mitigation: Use an alternative plugin such as ovs-subnet, or ovs-multitentant if delivering a multitentant service.