CVE-2016-3708
Last modified
CVE-2016-3708 is a vulnerability of currently unknown severity. Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | 3.2 |
References
- https://access.redhat.com/errata/RHSA-2016:1094Vendor Advisory
- https://access.redhat.com/errata/RHSA-2016:1094Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-3708?
How severe is CVE-2016-3708?
How do I fix CVE-2016-3708?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-3702Padding oracle flaw in CloudForms Management Engine (aka CFM…
- CVE-2016-3703Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly val…
- CVE-2016-3704Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to ge…
- CVE-2016-3705The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex…
- CVE-2016-3706Stack-based buffer overflow in the getaddrinfo function in s…7.5
- CVE-2016-3707The icmp_check_sysrq function in net/ipv4/icmp.c in the kern…
- CVE-2016-3709Possible cross-site scripting vulnerability in libxml after …6.1
- CVE-2016-3710The VGA module in QEMU improperly performs bounds checking o…8.8
- CVE-2016-3711HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Or…
- CVE-2016-3712Integer overflow in the VGA module in QEMU allows local gues…5.5
- CVE-2016-3713The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Li…
- CVE-2016-3714The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6…8.4
Are you affected by CVE-2016-3708?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
