A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
{
"source": "CPE_FIELD",
"cpe": [
"cpe:2.3:a:redhat:openshift:3.6:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.7:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.8:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.9:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.10:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:3.11:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openshift:4.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.6"
},
{
"last_affected": "3.7"
},
{
"last_affected": "3.8"
},
{
"last_affected": "3.9"
},
{
"last_affected": "3.10"
},
{
"last_affected": "3.11"
},
{
"last_affected": "4.1"
}
]
}