LiveActive security incident?Get immediate response
CVE Record

CVE-2015-5222: Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated...

Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This flaw lets an authenticated OpenShift Enterprise 3.0.0.0 user with build permissions run shell commands as root on arbitrary build pods. The issue is permission checking, not public unauthenticated access. Business urgency is highest where old OpenShift 3.0.0.0 clusters or build-capable accounts still exist.

Executive priority

Treat this as high priority only if legacy OpenShift Enterprise 3.0.0.0 is present. The vulnerability can turn build access into root-level control over build pods, but there is no cited evidence of active exploitation in the provided sources.

Technical view

CVE-2015-5222 is an authorization weakness in Red Hat OpenShift Enterprise 3.0.0.0. Remote authenticated users with build permissions can execute arbitrary shell commands with root privileges on arbitrary build pods through unspecified vectors. The public bundle does not provide CVSS, CWE, detailed affected package data, or technical exploit detail.

Likely exposure

Exposure is likely limited to Red Hat OpenShift Enterprise 3.0.0.0 environments where users or service accounts have build permissions. Modern or upgraded deployments may not be affected, but the provided data does not identify fixed versions beyond the Red Hat advisory reference.

Exploitation context

The source bundle does not cite active exploitation, public exploit code, or CISA KEV inclusion. Exploitation requires authentication and build permissions, but successful abuse would cross pod boundaries and gain root command execution on build pods.

Researcher notes

Key unknowns are the exact vulnerable packages, fixed builds, CVSS score, CWE classification, and technical vector. Avoid assuming broader Kubernetes or OpenShift versions are affected. Anchor validation on OpenShift Enterprise 3.0.0.0 and RHSA-2015:1650.

Mitigation direction

  • Review RHSA-2015:1650 and apply the vendor-supported remediation for affected OpenShift Enterprise systems.
  • Inventory any remaining OpenShift Enterprise 3.0.0.0 deployments.
  • Restrict build permissions to trusted administrators until remediation is confirmed.
  • Review build service accounts and remove unnecessary privileges.
  • Retire or isolate unsupported legacy clusters where vendor fixes cannot be applied.

Validation and detection

  • Confirm whether any OpenShift Enterprise 3.0.0.0 systems remain in production or staging.
  • Verify RHSA-2015:1650 remediation status against vendor guidance.
  • List users and service accounts with build permissions.
  • Review historical build activity for unexpected privileged command execution indicators.
  • Check change records for cluster upgrades or package updates after August 2015.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2015-5222 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.