4.6
CVSSv2

CVE-2020-1704

Published: 17/02/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) prior to 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift service mesh

Vendor Advisories

Synopsis Moderate: Red Hat OpenShift Service Mesh openshift-istio-kiali-rhel7-operator-container security update Type/Severity Security Advisory: Moderate Topic An update for openshift-istio-kiali-rhel7-operator-container is now available for Openshift Service Mesh 10 and 11Red Hat Product Security has r ...