The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://www.openwall.com/lists/oss-security/2014/06/05/19 | patch mailing list third party advisory |
https://github.com/openshift/openshift-extras/blob/enterprise-2.0/README.md#security-notice | third party advisory |