4.4
CVSSv2

CVE-2020-1708

Published: 07/02/2020 Updated: 12/02/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform 3.11

redhat openshift container platform 4.1

redhat openshift container platform 4.2

redhat openshift container platform 4.3

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 311 openshift-enterprise-mysql-apb security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-mysql-apb is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as ha ...
Synopsis Moderate: OpenShift Container Platform 4138 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Moderate: OpenShift Container Platform 4221 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scorin ...
Synopsis Moderate: OpenShift Container Platform 435 security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-apb-base-container, openshift-enterprise-mariadb-apb, openshift-enterprise-mysql-apb, and openshift-enterprise-postgresql-apb is now available for Red Hat ...