CVE-2018-1102
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Affected products
Red Hat, Inc. · atomic-openshiftReferences
https://access.redhat.com/errata/RHSA-2018:1227https://access.redhat.com/errata/RHSA-2018:1229https://access.redhat.com/errata/RHSA-2018:1231https://access.redhat.com/errata/RHSA-2018:1233https://access.redhat.com/errata/RHSA-2018:1235https://access.redhat.com/errata/RHSA-2018:1237https://access.redhat.com/errata/RHSA-2018:1239https://access.redhat.com/errata/RHSA-2018:1241https://access.redhat.com/errata/RHSA-2018:1243https://access.redhat.com/errata/RHSA-2019:0036https://bugzilla.redhat.com/show_bug.cgi?id=1562246