Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat OpenShift Origin 安全漏洞
Vulnerability Description
Red Hat OpenShift Origin是美国红帽(Red Hat)公司的一款开源平台即服务(PaaS)产品,它提供了一个云计算平台,开发者可在上面构建、测试、部署和运行应用程序,并支持Node.js和MongoDB等语言环境和框架。openshift-node是一套用于登录journal系统的专用RSA密钥。 Red Hat OpenShift Origin 1.1.6及之前版本中的openshift-node存在安全漏洞。本地攻击者可通过读取系统日志利用该漏洞获取敏感私钥信息。
CVSS Information
N/A
Vulnerability Type
N/A