PT-2020-14905 · Red Hat · Openshift Enterprise

Joseph Lamagna-Reiter

+1

·

Published

2020-03-09

·

Updated

2023-02-12

·

CVE-2020-1706

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openshift-enterprise versions 3.11 openshift-enterprise versions 4.1 through 4.3
Description A security issue has been discovered where multiple containers in the affected versions modify the permissions of /etc/passwd, allowing users other than root to modify it. An attacker with access to the running container can exploit this to add a user and escalate their privileges.
Recommendations For openshift-enterprise version 3.11, update to a version that includes the fix for this issue. For openshift-enterprise versions 4.1 through 4.3, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the containers to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1706

Affected Products

Openshift Enterprise