CVE-2014-3496
20.06.2014, 14:55
cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file.
Vendor | Product | Version |
---|---|---|
redhat | openshift | 1.2.8 |
redhat | openshift | 2.0 |
redhat | openshift | 2.0.1 |
redhat | openshift | 2.0.2 |
redhat | openshift | 2.0.3 |
redhat | openshift | 2.0.4 |
redhat | openshift | 2.0.5 |
redhat | openshift | 2.0.6 |
redhat | openshift | 2.1 |
redhat | openshift | 2.1.1 |
redhat | openshift_origin | 1.2.8 |
redhat | openshift_origin | 2.1 |
redhat | openshift_origin | 2.1.1 |
𝑥
= Vulnerable software versions
References