A flaw was found in the OpenShift Container Platform...
Moderate severity
Unreviewed
Published
Apr 28, 2026
to the GitHub Advisory Database
•
Updated Apr 28, 2026
Description
Published by the National Vulnerability Database
Apr 28, 2026
Published to the GitHub Advisory Database
Apr 28, 2026
Last updated
Apr 28, 2026
A flaw was found in the OpenShift Container Platform build system. A user with the
editClusterRole can inject arbitrary environment variables, such asLD_PRELOADorhttp_proxy, intodocker-buildcontainers through thebuildconfigs/instantiateAPI. This incomplete fix for a previous vulnerability allows for information disclosure, specifically impacting the confidentiality of build traffic.References