CVE-2018-1102
CVE-2018-1102
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Affected products
Red Hat, Inc. · atomic-openshiftWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://access.redhat.com/errata/RHSA-2018:1227https://access.redhat.com/errata/RHSA-2018:1229https://access.redhat.com/errata/RHSA-2018:1231https://access.redhat.com/errata/RHSA-2018:1233https://access.redhat.com/errata/RHSA-2018:1235https://access.redhat.com/errata/RHSA-2018:1237https://access.redhat.com/errata/RHSA-2018:1239https://access.redhat.com/errata/RHSA-2018:1241https://access.redhat.com/errata/RHSA-2018:1243https://access.redhat.com/errata/RHSA-2019:0036https://bugzilla.redhat.com/show_bug.cgi?id=1562246