CVE-2018-1102

CVE-2018-1102

Vendor Red Hat, Inc.
Product atomic-openshift
Weakness CWE-20 · Input validation
Published April 30, 2018
Last update August 5, 2024

CVSS base score

What the vulnerability does

01Description

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

Key dates

02Disclosure timeline

April 30, 2018 CVE published
August 5, 2024 Record updated