CVE-2016-8631

The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
References
Link Resource
http://www.securityfocus.com/bid/94110 Third Party Advisory VDB Entry Vendor Advisory
https://access.redhat.com/errata/RHSA-2016:2696 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8631 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:*

History

12 Feb 2023, 23:26

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2016-8631', 'name': 'https://access.redhat.com/security/cve/CVE-2016-8631', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1390735', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1390735', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 21:17

Type Values Removed Values Added
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2016-8631 -
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1390735 -

Information

Published : 2018-07-31 20:29

Updated : 2023-12-10 12:44


NVD link : CVE-2016-8631

Mitre link : CVE-2016-8631

CVE.ORG link : CVE-2016-8631


JSON object : View

Products Affected

redhat

  • openshift
CWE
CWE-20

Improper Input Validation