First published: Mon Aug 13 2018(Updated: )
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform | =3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15138 is rated as a moderate severity vulnerability due to its potential to expose confidential webhook tokens.
To fix CVE-2017-15138, update your OpenShift Container Platform to a patched version that addresses this vulnerability.
CVE-2017-15138 affects Red Hat OpenShift Container Platform version 3.9.
CVE-2017-15138 can be exploited by an attacker with sufficient privileges to view confidential webhook tokens.
No official workaround for CVE-2017-15138 has been provided; applying the update is strongly recommended.