CVE Database
/

CVE-2016-8651

Back to search

CVE-2016-8651

Published: Aug 1, 2018

Modified: Aug 6, 2024

PUBLISHED

CVSS v3.0

3.1

LOW

Description

An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.

VendorProductVersions

Red Hat

OpenShift Enterprise

affected
3

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

References

94935
vdb-entry
x_refsource_BID
RHSA-2016:2915
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now