Lucene search

K
cveRedhatCVE-2015-5305
HistoryNov 06, 2015 - 6:59 p.m.

CVE-2015-5305

2015-11-0618:59:00
CWE-22
redhat
web.nvd.nist.gov
37
cve-2015-5305
kubernetes
red hat openshift enterprise 3.0
directory traversal vulnerability
etcd

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

41.5%

Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.

Affected configurations

Nvd
Node
redhatopenshiftMatch3.0enterprise
VendorProductVersionCPE
redhatopenshift3.0cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

41.5%