CVE-2013-4364: High severity red hat openshift vulnerability
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
Other sources
Michael Scherer of Red Hat reports:
Description of problem:
oo-analytics-export and oo-analytics-import use a predictable filename in /tmp when exporting and importing data.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4364?
CVE-2013-4364 has a moderate severity level due to the potential impact of a symlink attack.
How do I fix CVE-2013-4364?
To fix CVE-2013-4364, update to a patched version of the 'openshift-origin-broker-util' package that addresses the symlink issue.
Which versions are affected by CVE-2013-4364?
CVE-2013-4364 affects Red Hat OpenShift Enterprise versions 1.0 and 2.0.
What is the impact of exploiting CVE-2013-4364?
Exploiting CVE-2013-4364 may allow local users to manipulate files using a symlink attack, potentially leading to unauthorized access.
Is CVE-2013-4364 a local or remote vulnerability?
CVE-2013-4364 is classified as a local vulnerability, as it requires local user access to exploit.