CVE-2016-5392: Infoleak
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list.
Other sources
Yanping Zhang of Red Hat reports:
It is possible for one user to view another users data due to the kubernetes watch cache delivering the wrong data in a multi tenant environment.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5392?
CVE-2016-5392 has a moderate severity rating due to its potential to expose sensitive information in a multi-tenant environment.
How do I fix CVE-2016-5392?
To mitigate CVE-2016-5392, it is recommended to upgrade to a patched version of Red Hat OpenShift that resolves this vulnerability.
Who is affected by CVE-2016-5392?
CVE-2016-5392 primarily affects users of Red Hat OpenShift Enterprise 3.2 who are operating in multi-tenant environments.
What type of vulnerability is CVE-2016-5392?
CVE-2016-5392 is classified as an information disclosure vulnerability that allows authenticated users to access sensitive data.
Can CVE-2016-5392 be exploited remotely?
Yes, CVE-2016-5392 can be exploited by remote authenticated users with knowledge of other project names in the Kubernetes API server.