CVE-2016-8631

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
References
Link Resource
http://www.securityfocus.com/bid/94110 Third Party Advisory VDB Entry Vendor Advisory
https://access.redhat.com/errata/RHSA-2016:2696 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631 Issue Tracking Vendor Advisory
http://www.securityfocus.com/bid/94110 Third Party Advisory VDB Entry Vendor Advisory
https://access.redhat.com/errata/RHSA-2016:2696 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 02:59

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/94110 - Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/bid/94110 - Third Party Advisory, VDB Entry, Vendor Advisory
References () https://access.redhat.com/errata/RHSA-2016:2696 - Vendor Advisory () https://access.redhat.com/errata/RHSA-2016:2696 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631 - Issue Tracking, Vendor Advisory
CVSS v2 : 4.0
v3 : 7.7
v2 : 4.0
v3 : 6.3

Information

Published : 2018-07-31 20:29

Updated : 2024-11-21 02:59


NVD link : CVE-2016-8631

Mitre link : CVE-2016-8631

CVE.ORG link : CVE-2016-8631


JSON object : View

Products Affected

redhat

  • openshift
CWE
CWE-20

Improper Input Validation