In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NRed Hat Openshift
APPRedhatall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-20578CRITICAL9.8PL ✓same product
IBM Cloud Pak for Security — pominięcie uwierzytelniania (Auth Bypass)
CVE-2014-0234CRITICAL9.8PL ✓same product
Red Hat OpenShift — domyślne hasło 'mooo' do konta MongoDB
CVE-2013-2060CRITICAL9.8PL ✓same product
Command Injection w OpenShift Origin przez metacharacters w URL
CVE-2014-0175CRITICAL9.8PL ✓same product
MCollective: domyślne hasło ustawiane podczas instalacji
CVE-2015-7501CRITICAL9.8PL ✓same product
RCE przez deserializację obiektów Java w produktach Red Hat (Apache Commons Collections)