CVE-2018-14632: Red Hat Openshift Container Platform

High severity, CVSS 7.7. EPSS: 1.9% chance of exploitation in the next 30 days.

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

Affected products

  • Red Hat Openshift Container Platform: up to and including 3.7; version 3.9 only; version 3.10 only; version 3.11 only
  • Starcounter-Jack JSON-Patch: affected versions not specified

Published 2018-09-06. Last modified 2026-06-17.