CVE-2017-15137: Red Hat Openshift

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.

Affected products

  • Red Hat Openshift: affected versions not specified
  • Red Hat Openshift Container Platform: version 3.9 only

Published 2018-07-16. Last modified 2026-06-17.