Hide Forgot
Michael Scherer (mscherer) reports: the file https://github.com/openshift/origin-server/blob/master/node-util/www/html/restorer.php used to restore application after being idle fails to safely handle user supplied data that is later used on the command line.
Created attachment 665754 [details] CVE-2012-5646-restorer.php.patch
Acknowledgements: This issue was discovered by Michael Scherer of the Red Hat Regional IT team.
This issue has been addressed in following products: RHEL 6 Version of OpenShift Enterprise Via RHSA-2013:0148 https://rhn.redhat.com/errata/RHSA-2013-0148.html
This issue has been addressed in OpenShift Online.