CVE-2016-8631

high

Description

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.

References

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631

https://access.redhat.com/errata/RHSA-2016:2696

http://www.securityfocus.com/bid/94110

Details

Source: Mitre, NVD

Published: 2018-07-31

Updated: 2023-02-12

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

Severity: High