CVE-2016-8631: Input Validation
Jordan Liggitt of Red Hat reports:
The OpenShift Enterprise 3 router sometimes selects new routes over old routes when determining claimed hostnames. This can result in a new route improperly overwriting an older route.
Other sources
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-8631?
CVE-2016-8631 is considered a medium severity vulnerability.
How does CVE-2016-8631 affect OpenShift users?
CVE-2016-8631 allows an attacker with route creation access to potentially overwrite existing routes and redirect network traffic.
How do I fix CVE-2016-8631 in my OpenShift environment?
To fix CVE-2016-8631, update your OpenShift environment to the latest patched version provided by Red Hat.
What versions of OpenShift are affected by CVE-2016-8631?
CVE-2016-8631 affects Red Hat OpenShift versions 3.0 and 3.3.
Who reported CVE-2016-8631?
CVE-2016-8631 was reported by Jordan Liggitt of Red Hat.