Vulnerability Details CVE-2017-15137
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.4%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 5.0
Products affected by CVE-2017-15137
-
cpe:2.3:a:redhat:openshift:-
-
cpe:2.3:a:redhat:openshift_container_platform:3.9