{"api_version":"1","generated_at":"2026-07-23T07:20:10+00:00","cve":"CVE-2018-1069","urls":{"html":"https://cve.report/CVE-2018-1069","api":"https://cve.report/api/cve/CVE-2018-1069.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-1069","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-1069"},"summary":{"title":"CVE-2018-1069","description":"Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2018-03-09 14:29:00","updated_at":"2019-10-09 23:38:00"},"problem_types":["CWE-732"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/103364","name":"103364","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Red Hat OpenShift Enterprise CVE-2018-1069 Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1552987","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1552987","refsource":"CONFIRM","tags":["Issue Tracking","Mitigation"],"title":"1552987 – (CVE-2018-1069) CVE-2018-1069 Networking: container networking does not prevent access to network resources","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-1069","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1069","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"1069","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift","cpe6":"3.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"1069","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openshift","cpe6":"3.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2018-1069","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-284 (Improper Access Control)","cweId":"CWE-284"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Red Hat, Inc.","product":{"product_data":[{"product_name":"OpenShift Enterprise","version":{"version_data":[{"version_affected":"=","version_value":"3.7"}]}}]}}]}},"references":{"reference_data":[{"url":"http://www.securityfocus.com/bid/103364","refsource":"MISC","name":"http://www.securityfocus.com/bid/103364"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1552987","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1552987"}]}},"nvd":{"publishedDate":"2018-03-09 14:29:00","lastModifiedDate":"2019-10-09 23:38:00","problem_types":["CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT_NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"},"exploitabilityScore":1.2,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:A/AC:M/Au:N/C:P/I:P/A:P","accessVector":"ADJACENT_NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.4},"severity":"MEDIUM","exploitabilityScore":5.5,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openshift:3.7:*:*:*:enterprise:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"1069","Ordinal":"116300","Title":"CVE-2018-1069","CVE":"CVE-2018-1069","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"1069","Ordinal":"1","NoteData":"Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"1069","Ordinal":"2","NoteData":"2018-03-09","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"1069","Ordinal":"3","NoteData":"2018-03-13","Type":"Other","Title":"Modified"}]}}}