CVE-2018-1102: Input Validation
A flaw was found in source-to-image as shipped with Openshift Enterprise 3.6. A improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Other sources
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1102?
CVE-2018-1102 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2018-1102?
To address CVE-2018-1102, it is recommended to update Red Hat OpenShift to the latest patched version.
What versions of OpenShift are affected by CVE-2018-1102?
CVE-2018-1102 affects Red Hat OpenShift Enterprise versions 3.0 through 3.9.
What kind of attack does CVE-2018-1102 facilitate?
CVE-2018-1102 facilitates privilege escalation attacks due to improper path validation in tar file extraction.
Is CVE-2018-1102 limited to certain deployments?
Yes, CVE-2018-1102 specifically impacts deployments of Red Hat OpenShift Enterprise 3.x versions.