CVE-2016-8631: Input Validation

Published Nov 1, 2016
·
Updated

Jordan Liggitt of Red Hat reports:

The OpenShift Enterprise 3 router sometimes selects new routes over old routes when determining claimed hostnames. This can result in a new route improperly overwriting an older route.

Other sources

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.

MITRE

Affected Software

2 affected components
redhat Openshift=3.0
redhat Openshift=3.3

Event History

Nov 1, 2016
Data Sourced
via Red Hat·06:53 PM
DescriptionSeverityAffected Software
Jul 31, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2016-8631?

CVE-2016-8631 is considered a medium severity vulnerability.

2

How does CVE-2016-8631 affect OpenShift users?

CVE-2016-8631 allows an attacker with route creation access to potentially overwrite existing routes and redirect network traffic.

3

How do I fix CVE-2016-8631 in my OpenShift environment?

To fix CVE-2016-8631, update your OpenShift environment to the latest patched version provided by Red Hat.

4

What versions of OpenShift are affected by CVE-2016-8631?

CVE-2016-8631 affects Red Hat OpenShift versions 3.0 and 3.3.

5

Who reported CVE-2016-8631?

CVE-2016-8631 was reported by Jordan Liggitt of Red Hat.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203