{"api_version":"1","generated_at":"2026-07-23T06:15:45+00:00","cve":"CVE-2016-8631","urls":{"html":"https://cve.report/CVE-2016-8631","api":"https://cve.report/api/cve/CVE-2016-8631.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-8631","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-8631"},"summary":{"title":"CVE-2016-8631","description":"The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-07-31 20:29:00","updated_at":"2023-02-12 23:26:00"},"problem_types":["CWE-20"],"metrics":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2016:2696","name":"RHSA-2016:2696","refsource":"REDHAT","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2016-8631","name":"https://access.redhat.com/security/cve/CVE-2016-8631","refsource":"MISC","tags":[],"title":"CVE-2016-8631 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/94110","name":"94110","refsource":"BID","tags":["Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"Red Hat OpenShift Enterprise CVE-2016-8631 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1390735","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1390735","refsource":"MISC","tags":[],"title":"1390735 – (CVE-2016-8631) CVE-2016-8631 OSE 3: Router sometimes selects new routes over old routes when determining claimed hostnames","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631","refsource":"CONFIRM","tags":["Issue Tracking","Vendor Advisory"],"title":"1390735 – (CVE-2016-8631) CVE-2016-8631 OSE 3: Router sometimes selects new routes over old routes when determining claimed hostnames","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-8631","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-8631","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"8631","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8631","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift","cpe6":"3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8631","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"8631","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift","cpe6":"3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2016-8631","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20","cweId":"CWE-20"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Red Hat","product":{"product_data":[{"product_name":"Openshift Enterprise","version":{"version_data":[{"version_affected":"=","version_value":"3"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.securityfocus.com/bid/94110","refsource":"MISC","name":"http://www.securityfocus.com/bid/94110"},{"url":"https://access.redhat.com/errata/RHSA-2016:2696","refsource":"MISC","name":"https://access.redhat.com/errata/RHSA-2016:2696"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631"}]},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.0"}]}},"nvd":{"publishedDate":"2018-07-31 20:29:00","lastModifiedDate":"2023-02-12 23:26:00","problem_types":["CWE-20"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"},"exploitabilityScore":3.1,"impactScore":4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"8631","Ordinal":"95286","Title":"CVE-2016-8631","CVE":"CVE-2016-8631","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"8631","Ordinal":"1","NoteData":"The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"8631","Ordinal":"2","NoteData":"2018-07-31","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"8631","Ordinal":"3","NoteData":"2018-08-01","Type":"Other","Title":"Modified"}]}}}