CVE-2016-3711

HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:openshift:3.2:*:*:*:enterprise:*:*:*

Configuration 2 (hide)

cpe:2.3:a:redhat:openshift_origin:-:*:*:*:*:*:*:*

History

12 Feb 2023, 23:19

Type Values Removed Values Added
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1322718', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1322718', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-3711', 'name': 'https://access.redhat.com/security/cve/CVE-2016-3711', 'tags': [], 'refsource': 'MISC'}
Summary An information disclosure flaw was discovered in haproxy as used by OpenShift Enterprise; a cookie with the name "OPENSHIFT_[namespace]_SERVERID" was set, which contained the internal IP address of a pod. HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.

02 Feb 2023, 21:16

Type Values Removed Values Added
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1322718 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-3711 -
Summary HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie. An information disclosure flaw was discovered in haproxy as used by OpenShift Enterprise; a cookie with the name "OPENSHIFT_[namespace]_SERVERID" was set, which contained the internal IP address of a pod.

Information

Published : 2016-06-08 17:59

Updated : 2023-12-10 11:46


NVD link : CVE-2016-3711

Mitre link : CVE-2016-3711

CVE.ORG link : CVE-2016-3711


JSON object : View

Products Affected

redhat

  • openshift
  • openshift_origin
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor