PT-2022-7296 · Cri-O+2 · Cri-O+2
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cri-o versions prior to 1.26.0
Description
A flaw exists that allows the addition of arbitrary lines into a container's
/etc/passwd file by using a specially crafted environment variable containing newlines. This can be used to bypass admission validation of the username or UID. This issue may impact the confidentiality, integrity, and availability of protected information.Recommendations
Update to version 1.26.0.
Use SELinux as an additional security control to prevent potential damage a container can cause with root privileges on the host.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Red Os
Cri-O