Lucene search

K
redhatRedHatRHSA-2016:1095
HistoryMay 19, 2016 - 8:30 p.m.

(RHSA-2016:1095) Moderate: Red Hat OpenShift Enterprise 3.1 security update

2016-05-1920:30:05
access.redhat.com
8

0.001 Low

EPSS

Percentile

41.0%

OpenShift Enterprise by Red Hat is the company’s cloud computing Platform-as-a-Service (PaaS) solution designed for on-premise or private cloud deployments.

Security Fix(es):

  • An origin validation vulnerability was found in OpenShift Enterprise. An attacker could potentially access API credentials stored in a web browser’s localStorage if anonymous access was granted to a service/proxy or pod/proxy API for a specific pod, and an authorized access_token was provided in the query parameter. (CVE-2016-3703)

This issue was discovered by Jordan Liggitt (Red Hat).

This update includes the following images:

openshift3/ose:v3.1.1.6-21
openshift3/ose-deployer:v3.1.1.6-20
openshift3/ose-docker-builder:v3.1.1.6-19
openshift3/ose-docker-registry:v3.1.1.6-9
openshift3/ose-f5-router:v3.1.1.6-20
openshift3/ose-haproxy-router:v3.1.1.6-9
openshift3/ose-keepalived-ipfailover:v3.1.1.6-9
openshift3/ose-pod:v3.1.1.6-9
openshift3/ose-recycler:v3.1.1.6-9
openshift3/ose-sti-builder:v3.1.1.6-19
openshift3/logging-auth-proxy:3.1.1-9
openshift3/logging-deployment:3.1.1-17
openshift3/logging-elasticsearch:3.1.1-11
openshift3/logging-fluentd:3.1.1-11
openshift3/logging-kibana:3.1.1-8
openshift3/metrics-deployer:3.1.1-7
openshift3/metrics-heapster:3.1.1-7
openshift3/node:v3.1.1.6-20
openshift3/openvswitch:v3.1.1.6-10

0.001 Low

EPSS

Percentile

41.0%