PT-2020-10145 · Red Hat · Openshift/Apb-Base

Joseph Lamagna-Reiter

+1

·

Published

2020-04-02

·

Updated

2020-04-03

·

CVE-2019-19348

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openshift/apb-base versions prior to 4.3.5 openshift/apb-base versions prior to 4.2.21 openshift/apb-base versions prior to 4.1.37 openshift/apb-base versions prior to 3.11.188-4
Description An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Recommendations For versions prior to 4.3.5, update to version 4.3.5 or later. For versions prior to 4.2.21, update to version 4.2.21 or later. For versions prior to 4.1.37, update to version 4.1.37 or later. For versions prior to 3.11.188-4, update to version 3.11.188-4 or later.

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19348

Affected Products

Openshift/Apb-Base