CVE-2016-8651
Last modified
CVE-2016-8651 is a low-severity vulnerability rated 3.1/10 on the CVSS scale. An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
Metrics
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | 3.0 |
| Redhat | Openshift Container Platform | 3.1 |
| Redhat | Openshift Container Platform | 3.2 |
| Redhat | Openshift Container Platform | 3.3 |
References
- http://www.securityfocus.com/bid/94935Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2915Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8651Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/94935Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2016:2915Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8651Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-8651?
How severe is CVE-2016-8651?
How do I fix CVE-2016-8651?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-8645The TCP stack in the Linux kernel before 4.8.10 mishandles s…
- CVE-2016-8646The hash_accept function in crypto/algif_hash.c in the Linux…
- CVE-2016-8647An input validation vulnerability was found in Ansible's mys…4.9
- CVE-2016-8648It was found that the Karaf container used by Red Hat JBoss …7.2
- CVE-2016-8649lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows a…
- CVE-2016-8650The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kern…
- CVE-2016-8652The auth component in Dovecot before 2.2.27, when auth-polic…
- CVE-2016-8653It was found that the JMX endpoint of Red Hat JBoss Fuse 6, …5.3
- CVE-2016-8654A heap-buffer overflow vulnerability was found in QMFB code …7.8
- CVE-2016-8655Race condition in net/packet/af_packet.c in the Linux kernel…7.8
- CVE-2016-8656Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vul…7
- CVE-2016-8657It was discovered that EAP packages in certain versions of R…
Are you affected by CVE-2016-8651?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
