V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-12195
CVE
Medium

A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given nam…

CVSS
6.5
Medium
EPSS
0.01
p68
Published
2017-01-01
Updated
2017-01-01
Description

A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.

Tags · CWE
Pre-auth
CWE-287
CAPEC-22
CAPEC-57
CAPEC-94
CAPEC-114
CAPEC-115
CAPEC-151
CAPEC-194
CAPEC-593
CAPEC-633
CAPEC-650
Affected products
AnsibleAnsible-asb-modulesAnsible-kubernetes-modulesAnsible-service-brokerApbApb-base-scriptsAtomic-openshiftAtomic-openshiftAtomic-openshiftAtomic-openshiftAtomic-openshift-deschedulerAtomic-openshift-node-problem-detectorCockpitCockpitCockpitCockpitContainernetworking-pluginsCri-oDumb-initElastic-curator
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.014 · p68
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-57 · CWE-287
└ via CAPEC-633 · CWE-287
└ via CAPEC-593 · CWE-287
└ via CAPEC-650 · CWE-287
└ via CAPEC-114 · CWE-287
└ via CAPEC-593 · CWE-287
└ via CAPEC-94 · CWE-287
└ via CAPEC-593 · CWE-287
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
ansibleTracked
ansible-asb-modulesTracked
ansible-kubernetes-modulesTracked
ansible-service-brokerTracked
apbTracked
apb-base-scriptsTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshiftTracked
atomic-openshift-deschedulerTracked
atomic-openshift-node-problem-detectorTracked
cockpitTracked
cockpitTracked
cockpitTracked
cockpitTracked
containernetworking-pluginsTracked
cri-oTracked
dumb-initTracked
elastic-curatorTracked
Showing first 20 of 417
Source databases
CVE
RED