An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:openshift_container_platform",
"source": "CPE_RANGE",
"extracted_events": [
{
"last_affected": "3.7"
}
]
},
{
"cpes": [
"cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift_container_platform:3.9:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:openshift_container_platform",
"source": "CPE_STRING",
"extracted_events": [
{
"introduced": "3.9"
},
{
"last_affected": "3.9"
},
{
"introduced": "3.10"
},
{
"last_affected": "3.10"
},
{
"introduced": "3.11"
},
{
"last_affected": "3.11"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "3.7"
}
]
}
]
}