REDHAT-BUG-1286745: Medium severity openshift vulnerability
Jordan Liggitt of Atomic OpenShift reports:
UPSTREAM: 17886: pod log location must validate container if provided #6113 has security implications, specifically a running pod could make an API call to view the logs of any pod running on the same Node.
External references:
https://github.com/openshift/origin/pull/6113
Affected Software
Event History
Frequently Asked Questions
What are the security implications of REDHAT-BUG-1286745?
REDHAT-BUG-1286745 allows a running pod to make API calls to view logs of any pod on the same Node, leading to potential information leakage.
How does REDHAT-BUG-1286745 affect OpenShift environments?
It could compromise pod confidentiality by enabling unauthorized access to logs across pods within the same Node.
What is the recommended mitigation for REDHAT-BUG-1286745?
To mitigate REDHAT-BUG-1286745, administrators should ensure proper restrictions on API access and validate log requests based on authentication and authorization levels.
Which version of OpenShift is affected by REDHAT-BUG-1286745?
REDHAT-BUG-1286745 affects multiple versions of OpenShift that allow pod log viewing without proper validation.
Is there a patch available for REDHAT-BUG-1286745?
Yes, patches and updates are typically provided by Red Hat that address the vulnerabilities highlighted in REDHAT-BUG-1286745.