CVE-2016-8631
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
31/07/2018
Last modified:
17/06/2026
Description
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:* | ||
| cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



