A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
| Software | From | Fixed in |
|---|---|---|
| redhat / openshift | 3.1 | 3.1.x |
| redhat / openshift | 3.0 | 3.0.x |
| redhat / openshift | 3.2 | 3.2.x |
| redhat / openshift | 3.7 | 3.7.x |
| redhat / openshift | 3.3 | 3.3.x |
| redhat / openshift | 3.4 | 3.4.x |
| redhat / openshift | 3.5 | 3.5.x |
| redhat / openshift | 3.6 | 3.6.x |
| redhat / openshift | 3.9 | 3.9.x |
| redhat / openshift | 3.8 | 3.8.x |