First published: Fri Aug 05 2016(Updated: )
openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Origin | <=1.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8945 has been classified as having a medium severity due to the exposure of sensitive credentials.
To fix CVE-2015-8945, upgrade to OpenShift Origin version 1.1.7 or later where the issue has been addressed.
CVE-2015-8945 affects OpenShift Origin versions 1.1.6 and earlier.
CVE-2015-8945 exposes sensitive router credentials stored as environment variables.
Yes, local users can exploit CVE-2015-8945 by reading the systemd journal to obtain sensitive private key information.