PT-2020-14905 · Red Hat · Openshift Enterprise
Joseph Lamagna-Reiter
+1
·
Published
2020-03-09
·
Updated
2023-02-12
·
CVE-2020-1706
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openshift-enterprise versions 3.11
openshift-enterprise versions 4.1 through 4.3
Description
A security issue has been discovered where multiple containers in the affected versions modify the permissions of /etc/passwd, allowing users other than root to modify it. An attacker with access to the running container can exploit this to add a user and escalate their privileges.
Recommendations
For openshift-enterprise version 3.11, update to a version that includes the fix for this issue.
For openshift-enterprise versions 4.1 through 4.3, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the containers to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Enterprise