PT-2020-14903 · Red Hat+1 · Openshift Service Mesh+1
Published
2020-02-17
·
Updated
2022-01-01
·
CVE-2020-1704
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenShift ServiceMesh (maistra) versions prior to 1.0.8
Description
A flaw was discovered in the /etc/passwd file, allowing an attacker with access to the container to modify it and potentially escalate their privileges. This issue affects the openshift/istio-kialia-rhel7-operator-container.
Recommendations
For versions prior to 1.0.8, update to version 1.0.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the container to minimize the risk of exploitation.
Fix
Incorrect Privilege Assignment
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Istio
Openshift Service Mesh