CVE-2019-10200 Information

Description

A flaw was discovered in OpenShift Container Platform 4 where by default users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network running on master nodes can retrieve security credentials for the master AWS IAM role allowing management access to AWS resources. With access to the security credentials the user then has access to the entire infrastructure. Impact to data and system availability is high.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Reference

https://bugzilla.redhat.com/show_bug.cgi?id=1730161 https://github.com/openshift/cluster-kube-apiserver-operator/pull/524

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.2

Share on: