PT-2020-14903 · Red Hat+1 · Openshift Service Mesh+1

Published

2020-02-17

·

Updated

2022-01-01

·

CVE-2020-1704

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenShift ServiceMesh (maistra) versions prior to 1.0.8
Description A flaw was discovered in the /etc/passwd file, allowing an attacker with access to the container to modify it and potentially escalate their privileges. This issue affects the openshift/istio-kialia-rhel7-operator-container.
Recommendations For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the container to minimize the risk of exploitation.

Fix

Incorrect Privilege Assignment

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1704

Affected Products

Istio
Openshift Service Mesh