CVE-2015-7561
Low
Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes
Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes
Exploit probability
1.2%
Published
August 20, 2024
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
GO-2023-1985
View original source
Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes
Open Source Vulnerabilities
GHSA-2h9c-34v6-3qmr
View original source
Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
05 / REFERENCES
Further evidence
- https://bugzilla.redhat.com/show_bug.cgi?id=1291963
- https://github.com/advisories/GHSA-2h9c-34v6-3qmr
- https://github.com/kubernetes/kubernetes/commit/e185b1028ac8459f7b451e1115399192e96f6ee9
- https://github.com/kubernetes/kubernetes/pull/18909
- https://github.com/kubernetes/kubernetes
- https://nvd.nist.gov/vuln/detail/CVE-2015-7561