CVE-2018-14632 describes an out-of-bounds write vulnerability in OpenShift Container Platform versions prior to 3.7, specifically when using the 'oc patch' functionality. This flaw, categorized as CWE-787, affects Red Hat and Starcounter Jack implementations of json_patch and OpenShift Container Platform. With a CVSS score of 7.7 (High), an attacker could exploit this remotely with low complexity to cause a denial of service against the OpenShift master API service, impacting cluster management. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.7CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:* | ||
3.9CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.9:*:*:*:*:*:*:* | ||
3.10CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.10:*:*:*:*:*:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:starcounter-jack:json-patch:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.