SB2016101704 - Authentication bypass in Red Hat OpenShift Container Platform
Published: October 17, 2016 Updated: October 18, 2016
Security Bulletin ID
SB2016101704
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Authentication bypass (CVE-ID: CVE-2016-7075)
The vulnerability allows a remote unauthenticated user to bypass authentication on the target system.The weakness is due to insufficient validation of X.509 client intermediate certificate hostname fields. By sending a specially crafted X.509 certificate to be processed, attackers can avoid authentication and access the system.
Succesful exploitation of the vulnerability may lead to further consequences or attacks.
Remediation
Install update from vendor's website.