CVE-2017-15137: Input Validation
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15137?
CVE-2017-15137 has a medium severity rating due to its potential to allow unauthorized image running in OpenShift.
How do I fix CVE-2017-15137?
To fix CVE-2017-15137, apply the latest security updates for Red Hat OpenShift and OpenShift Container Platform.
What software versions are affected by CVE-2017-15137?
CVE-2017-15137 affects all versions of Red Hat OpenShift and specifically the Red Hat OpenShift Container Platform version 3.9.
What can happen if I don't address CVE-2017-15137?
If CVE-2017-15137 is not addressed, unauthorized users could potentially run untrusted images from restricted registries.
Who is at risk from CVE-2017-15137?
Users with access to OpenShift environments are at risk from CVE-2017-15137 due to the improper enforcement of image import restrictions.