In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1029652 | issue tracking exploit vendor advisory |
https://github.com/openshift/origin-server/commit/f1abe972794e35a4bfba597694ce829990f14d39 | third party advisory patch |