An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/evanphx/json-patch(Go) | 0 | 0.5.2 | N/A |
| github.com/evanphx/json-patch(Go) | 3.0.0 | 3.0.1-0.20180525145409-4c9aadca8f89 | N/A |
CVSS Metrics