CVE-2014-0188: Red Hat Openshift

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

Affected products

  • Red Hat Openshift: up to and including 1.2.7; from 2.0, up to and including 2.0.5

Published 2014-04-24. Last modified 2026-06-17.