CRITICAL🇵🇱 Wersja polska

CVE-2013-4561

CVSS 9.1v3.1pub. 2022-06-30upd. 2024-11-21

In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Red Hat Openshift

    APP
    Redhat
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-20578CRITICAL9.8PL ✓same product

IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)

CVE-2014-0234CRITICAL9.8PL ✓same product

Red Hat OpenShift — domyślne hasło 'mooo' do konta MongoDB

CVE-2013-2060CRITICAL9.8PL ✓same product

Command Injection w OpenShift Origin przez metacharacters w URL

CVE-2014-0175CRITICAL9.8PL ✓same product

MCollective: domyślne hasło ustawiane podczas instalacji

CVE-2015-7501CRITICAL9.8PL ✓same product

RCE przez deserializację obiektów Java w produktach Red Hat (Apache Commons Collections)