VYPR
High severity8.8NVD Advisory· Published Apr 30, 2018· Updated Jun 17, 2026

CVE-2018-1102

CVE-2018-1102

Description

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Red Hat/Openshift10 versions
    cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*+ 9 more
    • cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.2:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.4:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.5:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.6:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.7:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.8:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:redhat:openshift:3.9:*:*:*:enterprise:*:*:*
  • Red Hat, Inc./atomic-openshiftv5
    Range: as shipped with Openshift Enterprise 3.x

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.