PT-2020-17857 · Cncf+2 · Kubernetes+3
Ismarc
·
Published
2020-06-22
·
Updated
2022-09-20
·
CVE-2020-4062
CVSS v3.1
9.0
Critical
| Vector | AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Conjur OSS Helm Chart versions prior to 2.0.0
Description
A critical issue in the Conjur OSS Helm Chart results in the installation of the Conjur Postgres database with an open port, allowing an attacker to gain full read and write access to the database. This enables the attacker to escalate privileges, assume full control, and write policies for full access to retrieve any secret. The systems impacted are only Conjur OSS systems deployed using this chart. A malicious actor with the IP address and port number of the Postgres database and access to the Kubernetes cluster can exploit this issue.
Recommendations
To remediate this vulnerability, clone the latest Helm Chart and follow the upgrade instructions.
If immediate remediation is not possible, mitigate some of the risk by deploying Conjur OSS on an isolated Kubernetes cluster or namespace, where no other workloads are running, and access is limited to security administrators via Role-Based Access Control (RBAC).
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Conjur Oss
Conjur Oss Helm Chart
Kubernetes
Postgres