CVE-2016-3738: High severity red hat openshift vulnerability
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3738?
CVE-2016-3738 has a medium severity rating due to its potential for privilege escalation.
How do I fix CVE-2016-3738?
To fix CVE-2016-3738, it is recommended to upgrade to a later version of Red Hat OpenShift Enterprise that addresses this vulnerability.
Who is affected by CVE-2016-3738?
CVE-2016-3738 affects users of Red Hat OpenShift Enterprise version 3.2.
What type of vulnerability is CVE-2016-3738?
CVE-2016-3738 is a privilege escalation vulnerability that allows remote authenticated access to sensitive resources.
What are the potential impacts of CVE-2016-3738?
The potential impacts of CVE-2016-3738 include unauthorized access to the Docker socket and escalation of privileges within the affected system.