First published: Mon Jan 11 2016(Updated: )
An authorization flaw was discovered in Kubernetes; the API server did not properly check user permissions when handling certain requests. An authenticated remote attacker could use this flaw to gain additional access to resources such as RAM and disk space.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openshift | <0:3.0.2.0-0.git.45.423f434.el7 | 0:3.0.2.0-0.git.45.423f434.el7 |
redhat/atomic-openshift | <0:3.1.1.6-1.git.0.b57e8bd.el7a | 0:3.1.1.6-1.git.0.b57e8bd.el7a |
redhat/heapster | <0:0.18.2-3.gitaf4752e.el7a | 0:0.18.2-3.gitaf4752e.el7a |
redhat/jenkins | <0:1.625.3-2.el7a | 0:1.625.3-2.el7a |
redhat/nodejs-align-text | <0:0.1.3-2.el7a | 0:0.1.3-2.el7a |
redhat/nodejs-ansi-green | <0:0.1.1-1.el7a | 0:0.1.1-1.el7a |
redhat/nodejs-ansi-wrap | <0:0.1.0-1.el7a | 0:0.1.0-1.el7a |
redhat/nodejs-anymatch | <0:1.3.0-1.el7a | 0:1.3.0-1.el7a |
redhat/nodejs-array-unique | <0:0.2.1-1.el7a | 0:0.2.1-1.el7a |
redhat/nodejs-arr-diff | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-arr-flatten | <0:1.0.1-1.el7a | 0:1.0.1-1.el7a |
redhat/nodejs-arrify | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-async-each | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-binary-extensions | <0:1.3.1-1.el7a | 0:1.3.1-1.el7a |
redhat/nodejs-braces | <0:1.8.2-2.el7a | 0:1.8.2-2.el7a |
redhat/nodejs-capture-stack-trace | <0:1.0.0-2.el7a | 0:1.0.0-2.el7a |
redhat/nodejs-chokidar | <0:1.4.1-2.el7a | 0:1.4.1-2.el7a |
redhat/nodejs-configstore | <0:1.4.0-1.el7a | 0:1.4.0-1.el7a |
redhat/nodejs-create-error-class | <0:2.0.1-2.el7a | 0:2.0.1-2.el7a |
redhat/nodejs-deep-extend | <0:0.3.2-2.el7a | 0:0.3.2-2.el7a |
redhat/nodejs-duplexer | <0:0.1.1-2.el7a | 0:0.1.1-2.el7a |
redhat/nodejs-duplexify | <0:3.4.2-1.el7a | 0:3.4.2-1.el7a |
redhat/nodejs-end-of-stream | <0:1.1.0-2.el7a | 0:1.1.0-2.el7a |
redhat/nodejs-error-ex | <0:1.2.0-1.el7a | 0:1.2.0-1.el7a |
redhat/nodejs-es6-promise | <0:3.0.2-2.el7a | 0:3.0.2-2.el7a |
redhat/nodejs-event-stream | <0:3.3.2-1.el7a | 0:3.3.2-1.el7a |
redhat/nodejs-expand-brackets | <0:0.1.4-1.el7a | 0:0.1.4-1.el7a |
redhat/nodejs-expand-range | <0:1.8.1-1.el7a | 0:1.8.1-1.el7a |
redhat/nodejs-extglob | <0:0.3.1-1.el7a | 0:0.3.1-1.el7a |
redhat/nodejs-filename-regex | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-fill-range | <0:2.2.3-1.el7a | 0:2.2.3-1.el7a |
redhat/nodejs-for-in | <0:0.1.4-1.el7a | 0:0.1.4-1.el7a |
redhat/nodejs-for-own | <0:0.1.3-1.el7a | 0:0.1.3-1.el7a |
redhat/nodejs-from | <0:0.1.3-2.el7a | 0:0.1.3-2.el7a |
redhat/nodejs-glob-base | <0:0.3.0-1.el7a | 0:0.3.0-1.el7a |
redhat/nodejs-glob-parent | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-got | <0:5.2.1-1.el7a | 0:5.2.1-1.el7a |
redhat/nodejs-graceful-fs | <0:4.1.2-1.el7a | 0:4.1.2-1.el7a |
redhat/nodejs-ini | <0:1.1.0-6.el7a | 0:1.1.0-6.el7a |
redhat/nodejs-is-binary-path | <0:1.0.1-1.el7a | 0:1.0.1-1.el7a |
redhat/nodejs-is-dotfile | <0:1.0.2-1.el7a | 0:1.0.2-1.el7a |
redhat/nodejs-is-equal-shallow | <0:0.1.3-1.el7a | 0:0.1.3-1.el7a |
redhat/nodejs-is-extendable | <0:0.1.1-1.el7a | 0:0.1.1-1.el7a |
redhat/nodejs-is-extglob | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-is-glob | <0:2.0.1-1.el7a | 0:2.0.1-1.el7a |
redhat/nodejs-is-npm | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-is-number | <0:2.1.0-1.el7a | 0:2.1.0-1.el7a |
redhat/nodejs-isobject | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-is-plain-obj | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-is-primitive | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-is-redirect | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-is-stream | <0:1.0.1-2.el7a | 0:1.0.1-2.el7a |
redhat/nodejs-kind-of | <0:3.0.2-1.el7a | 0:3.0.2-1.el7a |
redhat/nodejs-latest-version | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-lazy-cache | <0:1.0.2-1.el7a | 0:1.0.2-1.el7a |
redhat/nodejs-lodash.assign | <0:3.2.0-1.el7a | 0:3.2.0-1.el7a |
redhat/nodejs-lodash.baseassign | <0:3.2.0-1.el7a | 0:3.2.0-1.el7a |
redhat/nodejs-lodash.basecopy | <0:3.0.1-1.el7a | 0:3.0.1-1.el7a |
redhat/nodejs-lodash.bindcallback | <0:3.0.1-1.el7a | 0:3.0.1-1.el7a |
redhat/nodejs-lodash.createassigner | <0:3.1.1-1.el7a | 0:3.1.1-1.el7a |
redhat/nodejs-lodash.defaults | <0:3.1.2-1.el7a | 0:3.1.2-1.el7a |
redhat/nodejs-lodash.getnative | <0:3.9.1-1.el7a | 0:3.9.1-1.el7a |
redhat/nodejs-lodash.isarguments | <0:3.0.4-1.el7a | 0:3.0.4-1.el7a |
redhat/nodejs-lodash.isarray | <0:3.0.4-1.el7a | 0:3.0.4-1.el7a |
redhat/nodejs-lodash.isiterateecall | <0:3.0.9-1.el7a | 0:3.0.9-1.el7a |
redhat/nodejs-lodash.keys | <0:3.1.2-1.el7a | 0:3.1.2-1.el7a |
redhat/nodejs-lodash.restparam | <0:3.6.1-1.el7a | 0:3.6.1-1.el7a |
redhat/nodejs-lowercase-keys | <0:1.0.0-2.el7a | 0:1.0.0-2.el7a |
redhat/nodejs-map-stream | <0:0.1.0-2.el7a | 0:0.1.0-2.el7a |
redhat/nodejs-micromatch | <0:2.3.5-2.el7a | 0:2.3.5-2.el7a |
redhat/nodejs-mkdirp | <0:0.5.0-2.el7a | 0:0.5.0-2.el7a |
redhat/nodejs-nodemon | <0:1.8.1-2.el7a | 0:1.8.1-2.el7a |
redhat/nodejs-node-status-codes | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-normalize-path | <0:2.0.1-1.el7a | 0:2.0.1-1.el7a |
redhat/nodejs-object-assign | <0:4.0.1-1.el7a | 0:4.0.1-1.el7a |
redhat/nodejs-object.omit | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-optimist | <0:0.4.0-5.el7a | 0:0.4.0-5.el7a |
redhat/nodejs-osenv | <0:0.1.0-2.el7a | 0:0.1.0-2.el7a |
redhat/nodejs-os-homedir | <0:1.0.1-1.el7a | 0:1.0.1-1.el7a |
redhat/nodejs-os-tmpdir | <0:1.0.1-1.el7a | 0:1.0.1-1.el7a |
redhat/nodejs-package-json | <0:2.3.0-1.el7a | 0:2.3.0-1.el7a |
redhat/nodejs-parse-glob | <0:3.0.4-1.el7a | 0:3.0.4-1.el7a |
redhat/nodejs-parse-json | <0:2.2.0-2.el7a | 0:2.2.0-2.el7a |
redhat/nodejs-pause-stream | <0:0.0.11-2.el7a | 0:0.0.11-2.el7a |
redhat/nodejs-pinkie | <0:2.0.1-1.el7a | 0:2.0.1-1.el7a |
redhat/nodejs-pinkie-promise | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/nodejs-prepend-http | <0:1.0.1-2.el7a | 0:1.0.1-2.el7a |
redhat/nodejs-preserve | <0:0.2.0-1.el7a | 0:0.2.0-1.el7a |
redhat/nodejs-ps-tree | <0:1.0.1-1.el7a | 0:1.0.1-1.el7a |
redhat/nodejs-randomatic | <0:1.1.5-1.el7a | 0:1.1.5-1.el7a |
redhat/nodejs-rc | <0:1.1.2-1.el7a | 0:1.1.2-1.el7a |
redhat/nodejs-read-all-stream | <0:3.0.1-3.el7a | 0:3.0.1-3.el7a |
redhat/nodejs-readdirp | <0:2.0.0-2.el7a | 0:2.0.0-2.el7a |
redhat/nodejs-regex-cache | <0:0.4.2-1.el7a | 0:0.4.2-1.el7a |
redhat/nodejs-registry-url | <0:3.0.3-1.el7a | 0:3.0.3-1.el7a |
redhat/nodejs-repeat-element | <0:1.1.2-1.el7a | 0:1.1.2-1.el7a |
redhat/nodejs-semver | <0:5.1.0-1.el7a | 0:5.1.0-1.el7a |
redhat/nodejs-semver-diff | <0:2.1.0-1.el7a | 0:2.1.0-1.el7a |
redhat/nodejs-slide | <0:1.1.5-3.el7a | 0:1.1.5-3.el7a |
redhat/nodejs-split | <0:0.3.3-2.el7a | 0:0.3.3-2.el7a |
redhat/nodejs-stream-combiner | <0:0.2.1-2.el7a | 0:0.2.1-2.el7a |
redhat/nodejs-string-length | <0:1.0.1-1.el7a | 0:1.0.1-1.el7a |
redhat/nodejs-strip-json-comments | <0:1.0.2-2.el7a | 0:1.0.2-2.el7a |
redhat/nodejs-success-symbol | <0:0.1.0-1.el7a | 0:0.1.0-1.el7a |
redhat/nodejs-through | <0:2.3.4-4.el7a | 0:2.3.4-4.el7a |
redhat/nodejs-timed-out | <0:2.0.0-3.el7a | 0:2.0.0-3.el7a |
redhat/nodejs-touch | <0:1.0.0-2.el7a | 0:1.0.0-2.el7a |
redhat/nodejs-undefsafe | <0:0.0.3-1.el7a | 0:0.0.3-1.el7a |
redhat/nodejs-unzip-response | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-update-notifier | <0:0.6.0-1.el7a | 0:0.6.0-1.el7a |
redhat/nodejs-url-parse-lax | <0:1.0.0-1.el7a | 0:1.0.0-1.el7a |
redhat/nodejs-uuid | <0:2.0.1-1.el7a | 0:2.0.1-1.el7a |
redhat/nodejs-write-file-atomic | <0:1.1.2-2.el7a | 0:1.1.2-2.el7a |
redhat/nodejs-xdg-basedir | <0:2.0.0-1.el7a | 0:2.0.0-1.el7a |
redhat/openshift-ansible | <0:3.0.35-1.git.0.6a386dd.el7a | 0:3.0.35-1.git.0.6a386dd.el7a |
redhat/openvswitch | <0:2.4.0-1.el7 | 0:2.4.0-1.el7 |
redhat/origin-kibana | <0:0.5.0-1.el7a | 0:0.5.0-1.el7a |
Kubernetes Kubernetes |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.