CVE-2018-1085 is a critical misconfiguration vulnerability affecting Red Hat OpenShift Container Platform versions prior to 3.9.23 and 3.7.46. The flaw stems from improperly quoted values in the etcd.conf file, which disables SSL client certificate authentication for etcd. This allows unauthenticated remote attackers to access and manipulate all OpenShift cluster data, potentially leading to unauthorized node additions or a complete cluster shutdown. With a CVSS score of 9.8 (Critical), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in high impact to confidentiality, integrity, and availability. Despite its severity, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.9.31CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.