Path traversal in Red Hat OpenShift Container Platform - CVE-2024-7387
Published: September 19, 2024
Vulnerability identifier: #VU97614
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7387
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges within the container.
The vulnerability exists due to input validation error when processing directory traversal sequences in openshift/builder. A remote user can send a specially crafted HTTP request and escalate their permissions on the node running the container.
Affected software
Red Hat OpenShift Container Platform
APEX Cloud Platform for Red Hat OpenShift
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2024-7387
Install update from vendor's website.
Red Hat OpenShift Container Platform - addressed in versions 4.14.37, 4.12.66, 4.13.50, 4.15.33, 4.16.13
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00
External References
Related Security Bulletins
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Dell APEX Cloud Platform for Red Hat OpenShift