CVE-2016-3703: Medium severity red hat openshift vulnerability

Published Apr 25, 2016
·
Updated

Jordan Liggitt of Red Hat reports:

Malicious content can be loaded via the API proxy via a GET request if: 1. an authorized accesstoken is provided as a query parameter 2. anonymous access is granted to the service/proxy or pod/proxy API for the pod serving the content

That content has same-domain access to the browser localStorage if the web console and API server are hosted on the same domain. This gives the malicious content access to the logged in user's API credentials.

Other sources

Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an accesstoken in the query parameter.

MITRE

Affected Software

2 affected components
redhat Openshift=3.1
redhat Openshift=3.2

Event History

Apr 25, 2016
Data Sourced
via Red Hat·05:06 PM
DescriptionSeverityAffected Software
Jun 8, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2016-3703?

CVE-2016-3703 is classified as a high severity vulnerability due to potential unauthorized access to sensitive API credentials.

2

How do I fix CVE-2016-3703?

To mitigate CVE-2016-3703, users should upgrade Red Hat OpenShift Enterprise to version 3.3 or later, which has addressed this vulnerability.

3

Who is affected by CVE-2016-3703?

CVE-2016-3703 affects users of Red Hat OpenShift Enterprise versions 3.1 and 3.2 that have enabled anonymous access to services or pods.

4

What can attackers achieve with CVE-2016-3703?

Attackers exploiting CVE-2016-3703 can access API credentials stored in web browser localStorage, potentially leading to further exploitation.

5

Is there a workaround for CVE-2016-3703 before upgrading?

Yes, temporarily disabling anonymous access to the affected services can serve as a workaround until an upgrade is completed for CVE-2016-3703.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203