PT-2020-17857 · Cncf+2 · Kubernetes+3

Ismarc

·

Published

2020-06-22

·

Updated

2022-09-20

·

CVE-2020-4062

CVSS v3.1

9.0

Critical

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Conjur OSS Helm Chart versions prior to 2.0.0
Description A critical issue in the Conjur OSS Helm Chart results in the installation of the Conjur Postgres database with an open port, allowing an attacker to gain full read and write access to the database. This enables the attacker to escalate privileges, assume full control, and write policies for full access to retrieve any secret. The systems impacted are only Conjur OSS systems deployed using this chart. A malicious actor with the IP address and port number of the Postgres database and access to the Kubernetes cluster can exploit this issue.
Recommendations To remediate this vulnerability, clone the latest Helm Chart and follow the upgrade instructions. If immediate remediation is not possible, mitigate some of the risk by deploying Conjur OSS on an isolated Kubernetes cluster or namespace, where no other workloads are running, and access is limited to security administrators via Role-Based Access Control (RBAC).

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2020-4062
GHSA-MG2M-623J-WPXW

Affected Products

Conjur Oss
Conjur Oss Helm Chart
Kubernetes
Postgres