CVE-2015-8945: Medium severity red hat openshift origin vulnerability
Published Aug 5, 2016
·Updated
openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.
Affected Software
1 affected component
Openshift Origin<=1.1.6
Remediation
Patch Available
Event History
Aug 5, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8945?
CVE-2015-8945 has been classified as having a medium severity due to the exposure of sensitive credentials.
2
How do I fix CVE-2015-8945?
To fix CVE-2015-8945, upgrade to OpenShift Origin version 1.1.7 or later where the issue has been addressed.
3
What systems are affected by CVE-2015-8945?
CVE-2015-8945 affects OpenShift Origin versions 1.1.6 and earlier.
4
What type of information is exposed in CVE-2015-8945?
CVE-2015-8945 exposes sensitive router credentials stored as environment variables.
5
Can local users exploit CVE-2015-8945?
Yes, local users can exploit CVE-2015-8945 by reading the systemd journal to obtain sensitive private key information.