CVE-2016-8631
Summary
| CVE | CVE-2016-8631 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-31 20:29:00 UTC |
| Updated | 2023-02-12 23:26:00 UTC |
| Description | The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| CVE-2016-8631 - Red Hat Customer Portal | MISC | access.redhat.com | |
| Red Hat OpenShift Enterprise CVE-2016-8631 Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry, Vendor Advisory |
| 1390735 – (CVE-2016-8631) CVE-2016-8631 OSE 3: Router sometimes selects new routes over old routes when determining claimed hostnames | MISC | bugzilla.redhat.com | |
| 1390735 – (CVE-2016-8631) CVE-2016-8631 OSE 3: Router sometimes selects new routes over old routes when determining claimed hostnames | CONFIRM | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.