CVE-2018-1102: Red Hat Openshift

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

Affected products

  • Red Hat Openshift: version 3.0 only; version 3.1 only; version 3.2 only; version 3.3 only; version 3.4 only; version 3.5 only; …

Published 2018-04-30. Last modified 2026-06-17.