An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
| Software | From | Fixed in |
|---|---|---|
| redhat / openshift_container_platform | 3.9 | 3.9.x |
| redhat / openshift_container_platform | 3.11 | 3.11.x |
| redhat / openshift_container_platform | 3.10 | 3.10.x |
| redhat / openshift_container_platform | - | 3.7.x |
github.com/evanphx/json-patch
|
- | 0.5.2 |
github.com/evanphx/json-patch
|
3.0.0 | 3.0.1-0.20180525145409-4c9aadca8f89 |