First published: Thu Sep 19 2013(Updated: )
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift | =1.0 | |
Red Hat OpenShift | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4364 has a moderate severity level due to the potential impact of a symlink attack.
To fix CVE-2013-4364, update to a patched version of the 'openshift-origin-broker-util' package that addresses the symlink issue.
CVE-2013-4364 affects Red Hat OpenShift Enterprise versions 1.0 and 2.0.
Exploiting CVE-2013-4364 may allow local users to manipulate files using a symlink attack, potentially leading to unauthorized access.
CVE-2013-4364 is classified as a local vulnerability, as it requires local user access to exploit.