PT-2020-10146 · Red Hat · Openshift/Jenkins
Published
2020-03-18
·
Updated
2023-02-12
·
CVE-2019-19351
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openshift/jenkins versions 3.11 through 4
Description
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Recommendations
For versions 3.11 through 4, consider restricting access to the /etc/passwd file to prevent unauthorized modifications until a patch is available.
As a temporary workaround, limit the privileges of users with access to the container to minimize the risk of exploitation.
Fix
Incorrect Privilege Assignment
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openshift/Jenkins