An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
2020-04-02T20:15:15.393
2024-11-21T04:34:37.547
Modified
CVSSv3.1: 7.0 (HIGH)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | openshift | < 3.11.188-4 | Yes |
Application | redhat | openshift | < 4.1.37 | Yes |
Application | redhat | openshift | < 4.2.21 | Yes |
Application | redhat | openshift | < 4.3.5 | Yes |