SB2016101704 - Authentication bypass in Red Hat OpenShift Container Platform 



SB2016101704 - Authentication bypass in Red Hat OpenShift Container Platform

Published: October 17, 2016 Updated: October 18, 2016

Security Bulletin ID SB2016101704
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass (CVE-ID: CVE-2016-7075)

The vulnerability allows a remote unauthenticated user to bypass authentication on the target system.
The weakness is due to insufficient validation of X.509 client intermediate certificate hostname fields. By sending a specially crafted X.509 certificate to be processed, attackers can avoid authentication and access the system.
Succesful exploitation of the vulnerability may lead to further consequences or attacks.

Remediation

Install update from vendor's website.