CVE-2018-1103: Red Hat Source-To-Image

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Openshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could trick a user into using the command to copy files locally, from a pod, could override files outside of the target directory of the command.

Affected products

  • Red Hat Source-To-Image: before 1.1.10 (fixed in 1.1.10)

Published 2018-06-12. Last modified 2026-06-17.