MidnightBSD

Advisories for starcounter-jack

CVE-2018-14632 MEDIUM

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 7.7 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H 3.1 4.0

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-787,CWE-787,

Products Affected

Vendor Product Version
redhat openshift_container_platform 3.11
starcounter-jack json-patch -
redhat openshift_container_platform 3.10
redhat openshift_container_platform *
redhat openshift_container_platform 3.9