PT-2020-10146 · Red Hat · Openshift/Jenkins

Published

2020-03-18

·

Updated

2023-02-12

·

CVE-2019-19351

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openshift/jenkins versions 3.11 through 4
Description An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Recommendations For versions 3.11 through 4, consider restricting access to the /etc/passwd file to prevent unauthorized modifications until a patch is available. As a temporary workaround, limit the privileges of users with access to the container to minimize the risk of exploitation.

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2019-19351

Affected Products

Openshift/Jenkins