Path traversal in Red Hat OpenShift Container Platform - CVE-2024-7387

 

Path traversal in Red Hat OpenShift Container Platform - CVE-2024-7387

Published: September 19, 2024


Vulnerability identifier: #VU97614
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-7387
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges within the container.

The vulnerability exists due to input validation error when processing directory traversal sequences in openshift/builder. A remote user can send a specially crafted HTTP request and escalate their permissions on the node running the container.


Affected software

Red Hat OpenShift Container Platform
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2024-7387

Install update from vendor's website.

Red Hat OpenShift Container Platform - addressed in versions 4.14.37, 4.12.66, 4.13.50, 4.15.33, 4.16.13
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.01.00

External References

Related Security Bulletins