atomic-openshift: oc patch with json causes masterapi service crash
Published Sep 6, 2018
7.7
HIGHCVSS 3.1
EPSS 1.94%
Description
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
Affected products
-
- Version atomic-openshift-3.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Atomic-Openshift | n/a |
|
Configuration 1
- ≤ 3.7
- 3.9
- 3.10
- 3.11
Configuration 2
- n/a
No data.
Red Hat OpenShift Container Platform 3.10
atomic-openshift-0:3.10.66-1.git.0.91d1e89.el7
Fixed · RHSA-2018:2709
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.16-1.git.0.b48b8f8.el7
Fixed · RHBA-2018:2652
Red Hat OpenShift Container Platform 3.6
atomic-openshift-0:3.6.173.0.130-1.git.0.8d78a39.el7
Fixed · RHSA-2018:2654
Red Hat OpenShift Container Platform 3.7
atomic-openshift-0:3.7.72-1.git.0.925b9cd.el7
Fixed · RHSA-2018:2906
Red Hat OpenShift Container Platform 3.9
atomic-openshift-0:3.9.51-1.git.0.dc3a40b.el7
Fixed · RHSA-2018:2908
Red Hat OpenShift Container Platform 3.2
atomic-openshift
Affected
Red Hat OpenShift Container Platform 3.3
atomic-openshift
Affected
Red Hat OpenShift Container Platform 3.4
atomic-openshift
Affected
Red Hat OpenShift Container Platform 3.5
atomic-openshift
Affected
Red Hat OpenShift Container Platform 4
openshift
Not affected
Red Hat OpenShift Enterprise 3.0
openshift
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift-0:3.10.66-1.git.0.91d1e89.el7 | Fixed | RHSA-2018:2709 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.16-1.git.0.b48b8f8.el7 | Fixed | RHBA-2018:2652 |
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift-0:3.6.173.0.130-1.git.0.8d78a39.el7 | Fixed | RHSA-2018:2654 |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift-0:3.7.72-1.git.0.925b9cd.el7 | Fixed | RHSA-2018:2906 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-0:3.9.51-1.git.0.dc3a40b.el7 | Fixed | RHSA-2018:2908 |
| Red Hat OpenShift Container Platform 3.2 | atomic-openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 3.3 | atomic-openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 3.4 | atomic-openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 3.5 | atomic-openshift | Affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
| Red Hat OpenShift Enterprise 3.0 | openshift | Affected | n/a |
github.com/evanphx/json-patch
Go
Introduced 0 Fixed 0.5.2github.com/evanphx/json-patch
Go
Introduced 3.0.0+incompatible Fixed 3.0.1-0.20180525145409-4c9aadca8f89+incompatible
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/evanphx/json-patch | 0 | 0.5.2 |
| Go | github.com/evanphx/json-patch | 3.0.0+incompatible | 3.0.1-0.20180525145409-4c9aadca8f89+incompatible |
Remediation
Red Hat statement
A multi-master Openshift Container Platform cluster is more resilient, however a sustained attack would still have an important impact.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
AV:N/AC:L/Au:S/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.94% (0.01936) | 79.33th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.94% (0.01936) | 77.36th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.90% (0.00897) | 73.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.36% (0.02360) | 74.89th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.90% (0.00897) | 74.00th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.17% (0.00170) | 55.33th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.17% (0.00170) | 53.45th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00125) | 45.22th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.03% (0.01034) | 20.32th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.06% (0.02061) | 50.21th | v5 (v2026.06.15) |
| Apr 14, 2021 | 2.06% (0.02061) | 0.00th | v1 |
References (15)
- https://access.redhat.com/errata/RHBA-2018:2652 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2654 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2709 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2906 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2908 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-14632 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1625885 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14632 x_refsource_CONFIRMIssue TrackingPatchVendor Advisory
- https://github.com/advisories/GHSA-gxhv-3hwf-wjp9 Advisory
- https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03
- https://github.com/evanphx/json-patch/commit/4c9aadca8f89e349c999f04e28199e96e81aba03#diff-65c563bba473be9d94ce4d033f74810e x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/evanphx/json-patch/pull/57
- https://nvd.nist.gov/vuln/detail/CVE-2018-14632
- https://pkg.go.dev/vuln/GO-2021-0076
- https://www.cve.org/CVERecord?id=CVE-2018-14632
Change history (0)
No recorded changes yet.