Jordan Liggitt of Red Hat reports:
The OpenShift Enterprise 3 router sometimes selects new routes over old routes when determining claimed hostnames. This can result in a new route improperly overwriting an older route.
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
A flaw was found in source-to-image as shipped with Openshift Enterprise 3.6. A improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.