02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: redhatRed Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 0.58% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 45.2% of scored records. A rank, not a probability.
- NVD base score
- 7.1 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.0/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- Important. Red Hat's rating for its own products, not a CVSS rating.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2018-03-09 14:00Z8 YR AGO
- Last updated
- 2024-08-05 03:51Z2 YR AGO
- Reserved
- 2017-12-04
- Assigning CNA
- redhat
- Record state
- PUBLISHED
- Severity
- Not rated by the issuing CNA
- CNA CVSS vector
- Not published by the issuing CNA
- Weaknesses
- CWE-284Improper Access ControlPillar
- CWE-732Incorrect Permission Assignment for Critical ResourceClass
- CWE-20Improper Input ValidationClass
- Data version
- 5.1
- Document digest
- 5dab98042d780d0f240da281d4ccf5990dcf89eadd9ff67c20db74216f3aef2f
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms