CVE-2016-1906: Critical severity kubernetes dashboard vulnerability
Kubernetes api server: build config to a strategy that isn't allowed by policy
External reference: https://github.com/openshift/origin/issues/6556 https://github.com/openshift/origin/pull/6576
Other sources
Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1906?
CVE-2016-1906 has a medium severity rating due to its potential for privilege escalation.
How do I fix CVE-2016-1906?
To fix CVE-2016-1906, ensure that build configurations are only created with allowed types as per policy.
What systems are affected by CVE-2016-1906?
CVE-2016-1906 affects OpenShift environments that utilize Kubernetes.
Can I be attacked via CVE-2016-1906 remotely?
Yes, CVE-2016-1906 allows remote attackers to potentially gain higher privileges.
What impact does CVE-2016-1906 have on my OpenShift deployment?
CVE-2016-1906 could lead to unauthorized access or control over applications deploying on OpenShift.