First published: Wed Oct 19 2022(Updated: )
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4253 is a vulnerability found in the deployment script in the unsupported "OpenShift Extras" set of add-on scripts in Red Hat Openshift 1.
The severity of CVE-2013-4253 is high, with a severity value of 7.5.
Red Hat Openshift 1.0 is affected by CVE-2013-4253.
CVE-2013-4253 allows an attacker to install a default public key in the root user's authorized_keys file through the deployment script in the unsupported "OpenShift Extras" set of add-on scripts.
To mitigate CVE-2013-4253, users should avoid using the unsupported "OpenShift Extras" set of add-on scripts and ensure that the root user's authorized_keys file does not contain any unauthorized public keys.