It is reported that given the manifest data for a container that is not owned by a user that user will still be able to pull the container and access the contents of it.
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Red Hat OpenShift Enterprise 3.2
Red Hat OpenShift Container Platform 3.3
Via RHSA-2016:2915 https://access.redhat.com/errata/RHSA-2016:2915