CVE-2016-2149: Infoleak
Published Jun 8, 2016
·Updated
Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.
Affected Software
1 affected component
redhat Openshift=3.2
Event History
Jun 8, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-2149?
CVE-2016-2149 has a medium severity rating, allowing unauthorized access to sensitive log files.
2
How do I fix CVE-2016-2149?
To fix CVE-2016-2149, upgrade to a patched version of Red Hat OpenShift that addresses this vulnerability.
3
Who is affected by CVE-2016-2149?
CVE-2016-2149 affects users of Red Hat OpenShift Enterprise 3.2 who have remote authenticated access.
4
What does CVE-2016-2149 allow an attacker to do?
CVE-2016-2149 allows an attacker to read log files from another namespace by reusing a deleted namespace name.
5
Is CVE-2016-2149 a network-based vulnerability?
No, CVE-2016-2149 requires authenticated access, making it a local privilege escalation vulnerability.