Junglewise Threat Intelligence

CVE-2024-7387: Red Hat OpenShift Builder command injection via path traversal

CVE-2024-7387 · Severity: critical · CVSS 9.1 · Published 2024-09-17

Technologies: Red Hat OpenShift Container Platform. Vendors: Go, Red Hat.

Executive brief

Red Hat OpenShift, a platform for managing containerized applications, contains a vulnerability in its build system. A high-privileged user can exploit this flaw to escape their container and execute commands directly on the underlying server node. This could lead to a full takeover of the physical or virtual server hosting the OpenShift services, potentially compromising all other data and applications on that node.

Technical details

A path traversal vulnerability exists in the openshift/builder component of Red Hat OpenShift. When using the 'Docker' build strategy, an attacker with high privileges can use the 'spec.source.secrets.secret.destinationDir' attribute in a 'BuildConfig' definition to override executable files within the privileged build container. By traversing the file system and replacing critical binaries, the attacker can achieve command injection. Because the build container runs with elevated privileges, this allows the attacker to escape the container and execute arbitrary commands on the underlying OpenShift host node. The issue is addressed in various Red Hat errata (RHSA-2024:6691, etc.) and a specific commit in the openshift/builder repository.

Affected products

  • Red Hat OpenShift Container Platform <= 4.0.0 (Go package), 4.12, 4.13, 4.14, 4.15, 4.16

Timeline

  • 2024-09-17: disclosed
  • 2024-09-17: advisory
  • 2024-09-17: patched

References