REDHAT-BUG-2308661: High severity Red Hat OpenShift Container Platform vulnerability
A flaw was found in the OpenShift Container Platform where the initialization container for builds (git-clone) runs with elevated privileges. This misconfiguration allows an attacker with developer access to create a malicious .gitconfig file that executes arbitrary commands on a privileged build pod. As a result, the attacker can compromise the worker node hosting the build pod, potentially gaining access to all the workloads running on that node. The impact is critical, as it allows for the compromise of the node's identity and other nodes, depending on cluster configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2308661?
The severity of REDHAT-BUG-2308661 is categorized as high with a score of 7.
How do I fix REDHAT-BUG-2308661?
To fix REDHAT-BUG-2308661, ensure that the git-clone init container does not run with elevated privileges.
What impacts does REDHAT-BUG-2308661 have on security?
REDHAT-BUG-2308661 allows an attacker with developer access to execute arbitrary commands, posing a significant security risk.
In which software is REDHAT-BUG-2308661 found?
REDHAT-BUG-2308661 is found in the Red Hat OpenShift Container Platform.
What type of flaw is described in REDHAT-BUG-2308661?
REDHAT-BUG-2308661 describes a flaw where the initialization container for builds runs with elevated privileges due to misconfiguration.