CVE-2017-12195
Last modified
CVE-2017-12195 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. EPSS estimates a 1.39% chance of exploitation in the next 30 days.
Description
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | 3.4 |
| Redhat | Openshift Container Platform | 3.5 |
| Redhat | Openshift Container Platform | 3.6 |
| Redhat | Openshift Container Platform | 3.7 |
References
- https://access.redhat.com/errata/RHSA-2017:3188Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3389Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12195Issue Tracking, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3188Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:3389Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12195Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-12195?
How severe is CVE-2017-12195?
How do I fix CVE-2017-12195?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-1219IBM Tivoli Endpoint Manager is vulnerable to a XML External …
- CVE-2017-12190The bio_map_user_iov and bio_unmap_user functions in block/b…
- CVE-2017-12191A flaw was found in the CloudForms account configuration whe…
- CVE-2017-12192The keyctl_read_key function in security/keys/keyctl.c in th…
- CVE-2017-12193The assoc_array_insert_into_terminal_node function in lib/as…
- CVE-2017-12194A flaw was found in the way spice-client processed certain m…
- CVE-2017-12196undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Fin…4.8
- CVE-2017-12197It was found that libpam4j up to and including 1.8 did not p…
- CVE-2017-12199The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPr…
- CVE-2017-1220IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5…
- CVE-2017-12200The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPr…
- CVE-2017-1221IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does no…
Are you affected by CVE-2017-12195?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
