Red Hat OpenShift Container Platform
cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*
- < 4.21.0
A vulnerability exists in the OpenShift Container Platform build system, allowing users with the 'edit' ClusterRole to inject arbitrary environment variables into 'docker-build' containers via the 'buildconfigs/instantiate' API. This issue, stemming from an incomplete fix for a prior vulnerability, could lead to information disclosure by manipulating build traffic confidentiality.
Exploitation of this vulnerability could result in unauthorized injection of environment variables, potentially leading to information disclosure by intercepting and manipulating build traffic.
The vulnerability can be reproduced by a user with the 'edit' ClusterRole. Inject arbitrary environment variables, such as 'LD_PRELOAD' or 'http_proxy', into 'docker-build' containers through the 'buildconfigs/instantiate' API. The environment variable injection will propagate to the 'docker-build' container, which remains privileged.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.