Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
CVSS Information
N/A
Vulnerability Type
输入验证不恰当
Vulnerability Title
Red Hat Openshift Enterprise 安全漏洞
Vulnerability Description
Red Hat OpenShift是美国红帽(Red Hat)公司的一款平台即服务(PaaS)云计算平台,它可构建、测试、部署和运行应用程序。OpenShift Enterprise是一个开源的私有云版本。 Red Hat Openshift Enterprise 3.x版本中的‘source-to-image’函数存在安全漏洞,该漏洞源于在tar/tar.go文件中的ExtractTarStreamFromTarReader中,程序没有正确的校验tar文件的路径。攻击者可利用该漏洞提升权限。
CVSS Information
N/A
Vulnerability Type
N/A