First published: Thu Jul 13 2017(Updated: )
A user can create a project named "myProject", use that project for a while and then delete it. After the original project is deleted, another user can create a project called "myProject". Since the subjectaccessreview will now pass for this second user, they will be able to access metrics from the original project.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7517 has been assigned a medium severity rating due to its potential for unauthorized access to metrics by different users.
To fix CVE-2017-7517, ensure that access controls are properly configured to prevent unauthorized users from accessing metrics after a project is deleted.
CVE-2017-7517 affects Red Hat OpenShift 3.0.
CVE-2017-7517 is an access control vulnerability that allows unauthorized access to resources after a project has been deleted.
Yes, CVE-2017-7517 allows different users to create projects with the same name after the original project has been deleted, leading to potential access issues.