CVE-2016-3708: High severity red hat openshift vulnerability
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3708?
CVE-2016-3708 has been assigned a medium severity rating due to its potential impact on multi-tenant environments.
How do I fix CVE-2016-3708?
To fix CVE-2016-3708, ensure that the proper namespace isolation policies are configured and consider upgrading to a more recent version of Red Hat OpenShift.
Who is affected by CVE-2016-3708?
CVE-2016-3708 affects users of Red Hat OpenShift Enterprise 3.2 with multi-tenant SDN enabled.
What kind of vulnerability is CVE-2016-3708?
CVE-2016-3708 is a network resource access vulnerability that allows unauthorized access between isolated namespaces.
What software versions are vulnerable to CVE-2016-3708?
The vulnerable software version associated with CVE-2016-3708 is Red Hat OpenShift Enterprise 3.2.