The vendor explicitly identifies these products as affected by this CVE.
- atomic-openshift as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-clients as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-clients-redistributable as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-docker-excluder as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-excluder as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-hyperkube as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-hypershift as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-master as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-node as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-pod as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-sdn-ovs as a component of Red Hat OpenShift Container Platform 3.11
- atomic-openshift-template-service-broker as a component of Red Hat OpenShift Container Platform 3.11
- Summary
- A security issue was discovered in Kubernetes where an authorized user may be able to access private networks on the Kubernetes control plane components. Kubernetes clusters are only affected if an untrusted user can create or modify Node objects and proxy to them, or an untrusted user can create or modify StorageClass objects and access KubeControllerManager logs.
- Remediation
- Fix deferred
